Unauthenticated API Endpoint Exposure in Inductive Automation Ignition Software
CVE-2025-13913
5.4MEDIUM
What is CVE-2025-13913?
Inductive Automation's Ignition Software is susceptible to an exposure that allows unauthenticated remote access to an API endpoint. This vulnerability enables attackers to change the 'forgot password' recovery email address, potentially leading to unauthorized access to sensitive accounts. Proper security measures and remediation are essential to protect against such threats.
Affected Version(s)
Ignition Software 0 < 8.3.0
Ignition Software 8.3.0
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta reported this vulnerability to Inductive Automation.
