An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network
History

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 09:15:00 +0000

Type Values Removed Values Added
Description An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published: 2025-03-10T09:04:34.413Z

Updated: 2025-03-10T15:33:49.185Z

Reserved: 2025-02-21T08:32:26.973Z

Link: CVE-2025-27253

cve-icon Vulnrichment

Updated: 2025-03-10T15:33:45.461Z

cve-icon NVD

Status : Received

Published: 2025-03-10T09:15:10.897

Modified: 2025-03-10T09:15:10.897

Link: CVE-2025-27253

cve-icon Redhat

No data.