CVE-2025-27253
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 10, 2025
Updated: Mar 12, 2025
CWE ID 20
Summary
CVE-2025-27253 is a vulnerability affecting GE Vernova UR IED family devices from versions 7.0 to 8.60. This issue involves improper input validation, enabling an attacker to establish a TCP connection through port forwarding without validating the IP address and port. The attacker can potentially bypass firewall rules or send malicious traffic over the network. This vulnerability poses a significant risk to network security and should be addressed promptly by updating affected devices to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.