CVE-2025-27255
CVE-2025-27255
Título es
CVE-2025-27255
Lun, 10/03/2025 – 09:15
Tipo
CWE-798
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-27255
Descripción en
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
10/03/2025
10/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
8.00
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76
Enviar en el boletín
Off
