CVE-2025-27256

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Mar 10, 2025
Updated: Mar 12, 2025
CWE ID 306

Summary

CVE-2025-27256 is a critical vulnerability affecting the GE Vernova Enervista UR Setup application. This issue involves a missing SSH server authentication, resulting in an Authentication Bypass. Since the client connection lacks authentication, an attacker can execute a man-in-the-middle attack, potentially gaining unauthorized access to sensitive network information. This vulnerability poses a significant risk, and organizations running the affected application are advised to apply the necessary patches to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • EnerVista UR Setup

Affected Vendors

  • GE Energy