CVE-2025-27254: High severity GE Vernova Enervista UR Setup vulnerability
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Verify and correct the Windows registry setting used to disable the software’s startup authentication so that startup authentication cannot be bypassed by non-admin users.
GE Vernova EnerVista UR Setup (Windows registry) Windows registry value that disables startup authentication = Set to enable/startup-authentication (undo the authentication-bypass change)
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27254?
CVE-2025-27254 is classified as a high severity vulnerability due to its ability to allow authentication bypass.
How do I fix CVE-2025-27254?
To fix CVE-2025-27254, ensure that users are restricted from modifying the Windows registry settings related to the software's startup authentication.
Who is affected by CVE-2025-27254?
All users of GE Vernova EnerVista UR Setup are potentially affected by CVE-2025-27254.
What type of vulnerability is CVE-2025-27254?
CVE-2025-27254 is an improper authentication vulnerability that allows unauthorized access.
What can happen if CVE-2025-27254 is exploited?
Exploitation of CVE-2025-27254 can lead to unauthorized access to GE Vernova EnerVista UR Setup, compromising system security.