
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13913 is a Deserialization of Untrusted Data vulnerability (CWE-502) in Inductive Automation Ignition Software affecting all versions prior to 8.3.0. When a privileged Ignition user imports an external file containing a specially crafted payload, embedded malicious code executes during the deserialization process. The vulnerability was disclosed on March 12, 2026, via CISA ICS Advisory ICSA-26-071-06. It carries a CVSS v3.1 base score of 6.3 (Medium) per the vendor/CISA advisory, though NVD scores it at 6.8 (Medium) (CISA Advisory, CISA CSAF).
The root cause is improper deserialization of untrusted data (CWE-502) during the Ignition project import process. When a privileged user imports a maliciously crafted project or configuration file, the application deserializes the file contents without sufficient validation, allowing embedded code to execute with the permissions of the OS application service account running the Ignition process. Exploitation requires the attacker to be on an adjacent network, hold high privileges within the Ignition application, and induce (or directly perform) the import of a weaponized file — either through social engineering or by directly controlling a privileged account. No public proof-of-concept code has been identified at this time (CISA Advisory, CISA CSAF).
Successful exploitation allows an attacker to execute arbitrary malicious code with the OS-level permissions of the Ignition service account, potentially compromising confidentiality, integrity, and availability of the affected system. In environments where the Ignition service account has broad filesystem or domain privileges, this could enable lateral movement into OT/ICS networks, exfiltration of sensitive operational data, or disruption of industrial control processes. The vulnerability is particularly significant given Ignition's widespread deployment in critical infrastructure sectors globally (CISA Advisory).
No known public exploitation of CVE-2025-13913 has been reported to CISA, and the vulnerability is explicitly noted as not remotely exploitable. The EPSS score is approximately 0.027%, reflecting low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires adjacent network access, high application privileges, and user interaction (importing a malicious file), significantly limiting the attack surface (CISA Advisory).
cmd.exe, powershell.exe, /bin/bash, curl, wget) running under the Ignition service account.The primary remediation is to upgrade Inductive Automation Ignition Software from 8.1.x to version 8.3.0 or later. For systems that cannot be immediately upgraded, CISA and Inductive Automation recommend implementing the Ignition Security Hardening Guide (Appendix A) for both Linux and Windows, which includes running the Ignition service under a dedicated, least-privilege local account with restricted filesystem access. Additional best practices include restricting project imports to verified and trusted sources (using checksums or digital signatures), using multi-environment staging workflows (Dev/Test/Prod) to prevent untrusted data from reaching production, enforcing MFA for all privileged Ignition users, and segmenting Ignition gateways from corporate networks and Windows domains (CISA Advisory, Hardening Guide).
The vulnerability was reported to Inductive Automation by Nik Tsytsarkin, Ismail Aydemir, and Ryan Hall of Meta's security team, and subsequently coordinated with CISA by Nathan Boeger and Joel Specht of Inductive Automation. CISA published ICS Advisory ICSA-26-071-06 on March 12, 2026, noting no known public exploitation at the time of disclosure. No significant broader community or social media reactions have been identified beyond standard vulnerability database aggregation (CISA Advisory, CISA CSAF).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."