Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR...
Vulnerability Description
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-27257
Credits & Attribution
No credits recorded in the NVD database.
References
More from GE Vernova
View All →Affected Vendor
GE Vernova
View all reports →