ICSA-25-352-01
·
Published 2026-07-14
·
View on CISA ICS-CERT ↗
Inductive Automation Ignition (Update A)
CVSS 6.4
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to be granted direct SYSTEM-level code execution on the host operating system running the Ignition Gateway service on Windows systems.
CVEs (1)
Remediations
- Inductive Automation encourages users to do the following in order to reduce the risk of this vulnerability:
- Mitigation guidance covering OS-level service account hardening for both Windows and Linux is available in Annex A of the Ignition Security Hardening Guide. Application-level controls under a default installation are in development.
- For more information and updates, users should refer to Inductive Automation's Trust Portal.
Affected Vendors
Inductive Automation
Affected Products (1)
Inductive Automation
·
Ignition
8.1.x|8.3.x
Affected Sectors
Critical Manufacturing, Energy, Information Technology
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more