Improper Privilege Management in GE Vernova S1 Agile Configuration Software for Windows
CVE-2025-9038

7.5HIGH

Key Information:

Vendor

Ge Vernova

Vendor
CVE Published:
22 September 2025

What is CVE-2025-9038?

An improper privilege management vulnerability exists in GE Vernova S1 Agile Configuration Software for Windows that enables attackers to escalate their privileges. This issue particularly affects S1 Agile Configuration Software version 3.1 and prior. Users should ensure they are utilizing the latest patches and updates to mitigate potential exploitation.

Affected Version(s)

S1 Agile Configuration Software Windows 3.1 and previous version

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Charit Misra from DNV, Netherlands
.
CVE-2025-9038 : Improper Privilege Management in GE Vernova S1 Agile Configuration Software for Windows