Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Mar 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 10 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code. | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published: 2025-03-10T09:05:17.222Z
Updated: 2025-03-12T11:10:21.030Z
Reserved: 2025-02-21T08:32:26.973Z
Link: CVE-2025-27255
Updated: 2025-03-10T14:03:03.620Z
Status : Awaiting Analysis
Published: 2025-03-10T09:15:11.323
Modified: 2025-03-12T12:15:14.907
Link: CVE-2025-27255
No data.