A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network.
History

Tue, 07 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 07 Oct 2025 14:30:00 +0000

Type Values Removed Values Added
Description An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that establishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network.
Weaknesses CWE-15

Wed, 12 Mar 2025 11:15:00 +0000


Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 09:15:00 +0000

Type Values Removed Values Added
Description An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2025-10-07T14:16:49.710Z

Reserved: 2025-02-21T08:32:26.973Z

Link: CVE-2025-27253

cve-icon Vulnrichment

Updated: 2025-03-10T15:33:45.461Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-10T09:15:10.897

Modified: 2025-10-07T15:16:02.243

Link: CVE-2025-27253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.