CVE-2025-27257

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 10, 2025
Updated: Mar 12, 2025
CWE ID 345

Summary

CVE-2025-27257 is a cybersecurity vulnerability affecting GE Vernova UR IED family devices. Maliciously crafted firmware can be installed on these devices as the verification process is insufficient. Authentication is required to execute the attack, and the vulnerability lies in the lack of authentication checks on the device itself, bypassing the firmware signature verification enforced in Enervista UR Setup. This weakness could lead to unauthorized firmware installation, potentially jeopardizing the security and functionality of the devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share