CVE-2025-3222: Smallworld SWMFS Improper Authentication
Published Nov 7, 2025
·Updated
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
Affected Software
2 affected components
GE Vernova Smallworld<5.3.3
GE Vernova Smallworld<5.3.4
Remediation
Information
GE Vernova recommends that users upgrade to the appropriate non-affected version listed above in accordance with their use case and architecture as this is the most complete method to address the Vulnerability.
Also, users are strongly advised to follow the SDG instructions. The complete SDG can be found in the Smallworld Documentation.
To obtain the latest version of SWMFS, please contact your local support representative at Customer Center.
Event History
Nov 7, 2025
CVE Published
via MITRE·04:28 PM
Data Sourced
via MITRE·04:28 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3222?
CVE-2025-3222 is classified as a critical vulnerability due to its potential to allow authentication abuse.
2
How do I fix CVE-2025-3222?
To fix CVE-2025-3222, update GE Vernova Smallworld to version 5.3.4 for Windows or 5.3.4 for Linux.
3
Which versions of GE Vernova Smallworld are affected by CVE-2025-3222?
CVE-2025-3222 affects GE Vernova Smallworld versions up to and including 5.3.3 for Linux and 5.3.4 for Windows.
4
What type of vulnerability is CVE-2025-3222?
CVE-2025-3222 is an improper authentication vulnerability that can lead to authentication abuse.
5
Is CVE-2025-3222 specific to any operating system?
Yes, CVE-2025-3222 affects GE Vernova Smallworld on both Windows and Linux operating systems.