CVE-2025-27257: Medium severity GE Vernova UR IED family vulnerability
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27257?
CVE-2025-27257 is rated as a critical vulnerability due to its potential to allow unauthorized firmware installation.
How do I fix CVE-2025-27257?
To fix CVE-2025-27257, ensure you are using the latest version of the firmware and verify all installations against trusted sources.
Who is affected by CVE-2025-27257?
CVE-2025-27257 affects devices in the GE Vernova UR IED family and the GE Enervista UR Setup software.
What kind of attack can be executed using CVE-2025-27257?
An authenticated user could install modified firmware, potentially leading to system compromise or data integrity issues.
Is CVE-2025-27257 exploitability dependent on user authentication?
Yes, CVE-2025-27257 requires that the attacker has authenticated access to exploit the vulnerability.