Inductive Automation Ignition Software
Inductive Automation Ignition Software versions below 8.3.0 contain a critical deserialization vulnerability (CVE-2025-13913) that allows privileged users to execute malicious code with OS service account permissions through specially crafted file imports. The vulnerability affects critical infrastructure worldwide and requires immediate patching to version 8.3.0 or greater.
Summary
Inductive Automation Ignition Software versions below 8.3.0 contain a critical deserialization vulnerability (CVE-2025-13913) that allows privileged users to execute malicious code with OS service account permissions through specially crafted file imports. The vulnerability affects critical infrastructure worldwide and requires immediate patching to version 8.3.0 or greater.
Indicators of Compromise
- cve — CVE-2025-13913