Improper Authentication Vulnerability in GE Vernova Smallworld for Windows and Linux
CVE-2025-3222

9.3CRITICAL

Key Information:

Vendor

Ge Vernova

Vendor
CVE Published:
7 November 2025

What is CVE-2025-3222?

An improper authentication vulnerability exists in GE Vernova's Smallworld, affecting both Windows and Linux platforms. This flaw could allow attackers to leverage authentication abuse, potentially granting unauthorized access to sensitive systems. Users of Smallworld versions 5.3.3 and prior for Linux, as well as 5.3.4 and prior for Windows, are particularly at risk. It is crucial for organizations to assess their systems and apply necessary security measures to mitigate potential threats.

Affected Version(s)

Smallworld Windows 5.3.3

Smallworld Windows 5.3.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Theo Gobinet
Azael Martin
.
CVE-2025-3222 : Improper Authentication Vulnerability in GE Vernova Smallworld for Windows and Linux