Privilege Escalation Vulnerability in GE Vernova EnerVista UR Setup
CVE-2025-27255

8HIGH

Key Information:

Vendor

Ge Vernova

Vendor
CVE Published:
10 March 2025

What is CVE-2025-27255?

The vulnerability in GE Vernova EnerVista UR Setup involves the use of hard-coded credentials, which can be exploited to enable privilege escalation. The local user database relies on a hardcoded password that can be retrieved through analysis of the application code. This weakness presents significant security risks, as attackers can gain unauthorized access to sensitive functionalities and data within the system.

Affected Version(s)

EnerVista UR Setup 8.42

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diego Giubertoni of Nozomi Networks found this bug during a security research activity.
.