Python Scripting Vulnerability in Ignition SCADA Applications by Inductive Automation
CVE-2025-13911
What is CVE-2025-13911?
The vulnerability affects Ignition SCADA applications utilizing Python scripting for automation, resulting from inadequate security controls that allow unrestricted import and execution of Python libraries. A critical issue emerges when the Ignition service account possesses excessive system permissions, enabling the execution of malicious project files uploaded by authenticated administrators. These files can contain Python scripts designed to initiate bind shell capabilities, executing with the same privileges as the Ignition Gateway process, typically operating with SYSTEM-level permissions on Windows. Alternative execution patterns may similarly exploit this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Ignition 8.1.x
Ignition 8.3.x
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
