CVE-2025-13913: Inductive Automation Ignition Software Deserialization of Untrusted Data
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13913?
CVE-2025-13913 is considered a high severity vulnerability due to its potential for unauthorized access to the 'forgot password' feature.
How do I fix CVE-2025-13913?
To mitigate CVE-2025-13913, ensure that the software is updated to the latest version with security patches applied.
What kind of attack can be executed using CVE-2025-13913?
An attacker can exploit CVE-2025-13913 to change the recovery email address linked to user accounts, potentially gaining access to those accounts.
Is authentication required to exploit CVE-2025-13913?
No, CVE-2025-13913 is vulnerable through an unauthenticated API endpoint, making it accessible to attackers without login credentials.
Which software versions are affected by CVE-2025-13913?
CVE-2025-13913 affects all versions of Inductive Automation Ignition Software prior to receiving the security patch.