CVE-2025-13911
Last modified
CVE-2025-13911 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-13911?
How severe is CVE-2025-13911?
How do I fix CVE-2025-13911?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13906The WP Flot plugin for WordPress is vulnerable to Stored Cro…6.4
- CVE-2025-13907The CSS3 Buttons plugin for WordPress is vulnerable to Store…6.4
- CVE-2025-13908The The Tooltip plugin for WordPress is vulnerable to Stored…6.4
- CVE-2025-13909The system accepts authentication requests without sufficien…4.3
- CVE-2025-1391A flaw was found in the Keycloak organization feature, which…5.4
- CVE-2025-13910The WP-WebAuthn plugin for WordPress is vulnerable to Unauth…6.1
- CVE-2025-13912Multiple constant-time implementations in wolfSSL before ver…1
- CVE-2025-13913A privileged Ignition user, intentionally or otherwise, impo…6.8
- CVE-2025-13914A Key Exchange without Entity Authentication vulnerability i…8.1
- CVE-2025-13915IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 cou…9.8
- CVE-2025-13916IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expe…7.5
- CVE-2025-13917WSS Agent, prior to 9.8.5, may be susceptible to a Elevation…7
Are you affected by CVE-2025-13911?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
