CVE-2025-27253 - CVE House
Back to Database
Status published Medium CVE-2025-27253

A CWE-15 "External Control of System or Configuration Setting" in GE Vernova...

Vulnerability Description

A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27253

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

N60 multilin, B30 Multilin, B90 Multilin, C30 Multilin, C60 Multilin, C70 Multilin, C95 Multilin, D30 Multilin, D60 Multilin, F35 Multilin, F60 Multilin, G30 Multilin, G60 Multilin, L30 Multilin, L60 Multilin, L90 Multilin, M60 Multilin, T35 Multilin, T60 Multilin
Vulnerable Versions:
7.0

Timeline

Official Publish: March 10th, 2025
Last Modified: October 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.