Authentication Bypass in GE Vernova Enervista UR Setup Application
CVE-2025-27256
8.3HIGH
What is CVE-2025-27256?
A significant vulnerability exists in the GE Vernova Enervista UR Setup application, characterized by a missing authentication mechanism for SSH server connections. This gap allows unauthorized access, enabling an attacker to execute a man-in-the-middle attack on the network. Consequently, sensitive data could be intercepted, altering the overall security posture of the affected systems.
Affected Version(s)
EnerVista UR Setup 7.0 <= 8.60
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Giubertoni of Nozomi Networks found this bug during a security research activity.