Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v9q-jpv7-7w2m

Опубликовано: 10 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.

EPSS

Процентиль: 4%
0.0002
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 6.1
nvd
11 месяцев назад

Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.

CVSS3: 6.1
fstec
11 месяцев назад

Уязвимость электронных устройств GE Vernova Intelligent Electronic Device (IED) серии Universal Relay (UR), связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 4%
0.0002
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-345