Path Traversal Vulnerability in GE Vernova WorkstationST on Windows
CVE-2025-3223
5.9MEDIUM
What is CVE-2025-3223?
A Path Traversal vulnerability exists in the GE Vernova WorkstationST on Windows, specifically within the EGD Configuration Server modules. This vulnerability allows an attacker to manipulate input to access files and directories that are otherwise restricted. Consequently, unauthorized users can exploit this weakness to potentially overwrite critical files. It is essential for users of WorkstationST versions 07.10.10C and earlier to address this issue to safeguard against potential data compromise.
Affected Version(s)
WorkstationST Windows WorkstationST V07.10.10C and earlier
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ricardo Pelaz GarcĂa
Roberto Garcia Hervás