CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-27257
Severity
MEDIUM
CVSS
6.1
EPSS
0.17%
Original NVD Description
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.