CVE-2025-27255
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
An attacker can bypass the authentication required by the software
March 7, 2025
This issue affect the GE Vernova EnerVista UR Setup software version 8.42
CVE-2025-27255
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
8.0
Update the EnerVista UR Setup software to the latest released version
Diego Giubertoni of Nozomi Networks
Nozomi Networks Labs curates threat and vulnerability insights that are continuously fed into the Nozomi Networks platform to ensure our sensors can detect existing and emerging threats and vulnerabilities that threaten customers environments.
Learn more

