<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:16:44 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-360973</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-360973</link>
      <description>EUVD-2026-360973</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-360973</guid>
    </item>
    <item>
      <title>fkie_cve-2025-13911</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-13911</link>
      <description>&lt;p&gt;Ignition by Inductive Automation, when installed with default OS service
 account settings, may expose the host system to an elevated code 
execution risk via the gateway backup restore functionality. An 
authenticated user with Gateway Administrator privileges can import a 
malicious gateway backup (.gwbk) file containing crafted project 
resources, scripts, or modules, resulting in code execution on the host 
system. This affects both Windows and Linux installations. On Windows, 
default installations often run the Ignition service as NT 
AUTHORITY\SYSTEM, resulting in code execution with full local system 
privileges. On Linux, default installations commonly run the Ignition 
service as root or with elevated privileges. Specific privilege level 
depends on installation configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ignition by Inductive Automation, when installed with default OS service
 account settings, may expose the host system to an elevated code 
execution risk via the gateway backup restore functionality. An 
authenticated user with Gateway Administrator privileges can import a 
malicious gateway backup (.gwbk) file containing crafted project 
resources, scripts, or modules, resulting in code execution on the host 
system. This affects both Windows and Linux installations. On Windows, 
default installations often run the Ignition service as NT 
AUTHORITY\SYSTEM, resulting in code execution with full local system 
privileges. On Linux, default installations commonly run the Ignition 
service as root or with elevated privileges. Specific privilege level 
depends on installation configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-13911</guid>
    </item>
    <item>
      <title>GHSA-wmxh-4mgr-2w85</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wmxh-4mgr-2w85</link>
      <description>&lt;p&gt;The vulnerability affects Ignition SCADA applications where Python 
scripting is utilized for automation purposes. The vulnerability arises 
from the absence of proper security controls that restrict which Python 
libraries can be imported and executed within the scripting environment.
 The core issue lies in the Ignition service account having system 
permissions beyond what an Ignition privileged user requires. When an 
authenticated administrator uploads a malicious project file containing 
Python scripts with bind shell capabilities, the application executes 
these scripts with the same privileges as the Ignition Gateway process, 
which typically runs with SYSTEM-level permissions on Windows. 
Alternative code execution patterns could lead to similar results.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The vulnerability affects Ignition SCADA applications where Python 
scripting is utilized for automation purposes. The vulnerability arises 
from the absence of proper security controls that restrict which Python 
libraries can be imported and executed within the scripting environment.
 The core issue lies in the Ignition service account having system 
permissions beyond what an Ignition privileged user requires. When an 
authenticated administrator uploads a malicious project file containing 
Python scripts with bind shell capabilities, the application executes 
these scripts with the same privileges as the Ignition Gateway process, 
which typically runs with SYSTEM-level permissions on Windows. 
Alternative code execution patterns could lead to similar results.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wmxh-4mgr-2w85</guid>
    </item>
    <item>
      <title>ICSA-25-352-01 — Inductive Automation Ignition (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-352-01</link>
      <description>&lt;p&gt;Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ignition by Inductive Automation, when installed with default OS service account settings, may expose the host system to an elevated code execution risk via the gateway backup restore functionality. An authenticated user with Gateway Administrator privileges can import a malicious gateway backup (.gwbk) file containing crafted project resources, scripts, or modules, resulting in code execution on the host system. This affects both Windows and Linux installations. On Windows, default installations often run the Ignition service as NT AUTHORITY\SYSTEM, resulting in code execution with full local system privileges. On Linux, default installations commonly run the Ignition service as root or with elevated privileges. Specific privilege level depends on installation configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-352-01</guid>
    </item>
  </channel>
</rss>
