CVE-2025-27255 - CERT CVE
ID CVE-2025-27255
Sažetak Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
Reference
CVSS
Base: 8.0
Impact: 5.5
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Zadnje važnije ažuriranje 12-03-2025 - 12:15
Objavljeno 10-03-2025 - 09:15