diff --git a/advisories/unreviewed/2025/03/GHSA-5v9q-jpv7-7w2m/GHSA-5v9q-jpv7-7w2m.json b/advisories/unreviewed/2025/03/GHSA-5v9q-jpv7-7w2m/GHSA-5v9q-jpv7-7w2m.json new file mode 100644 index 00000000000..e2734a7121e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5v9q-jpv7-7w2m/GHSA-5v9q-jpv7-7w2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v9q-jpv7-7w2m", + "modified": "2025-03-10T09:31:49Z", + "published": "2025-03-10T09:31:49Z", + "aliases": [ + "CVE-2025-27257" + ], + "details": "Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware.\nThe firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27257" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fh83-6qjg-wh4v/GHSA-fh83-6qjg-wh4v.json b/advisories/unreviewed/2025/03/GHSA-fh83-6qjg-wh4v/GHSA-fh83-6qjg-wh4v.json new file mode 100644 index 00000000000..d99561d3661 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fh83-6qjg-wh4v/GHSA-fh83-6qjg-wh4v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh83-6qjg-wh4v", + "modified": "2025-03-10T09:31:48Z", + "published": "2025-03-10T09:31:48Z", + "aliases": [ + "CVE-2025-27255" + ], + "details": "Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27255" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gjhg-f944-56m2/GHSA-gjhg-f944-56m2.json b/advisories/unreviewed/2025/03/GHSA-gjhg-f944-56m2/GHSA-gjhg-f944-56m2.json new file mode 100644 index 00000000000..c131d2e3c72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gjhg-f944-56m2/GHSA-gjhg-f944-56m2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjhg-f944-56m2", + "modified": "2025-03-10T09:31:48Z", + "published": "2025-03-10T09:31:48Z", + "aliases": [ + "CVE-2025-27256" + ], + "details": "Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27256" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j5vp-q6vg-25mf/GHSA-j5vp-q6vg-25mf.json b/advisories/unreviewed/2025/03/GHSA-j5vp-q6vg-25mf/GHSA-j5vp-q6vg-25mf.json new file mode 100644 index 00000000000..89277b1a389 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j5vp-q6vg-25mf/GHSA-j5vp-q6vg-25mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5vp-q6vg-25mf", + "modified": "2025-03-10T09:31:48Z", + "published": "2025-03-10T09:31:48Z", + "aliases": [ + "CVE-2025-27253" + ], + "details": "An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27253" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pw5w-rmc5-f87r/GHSA-pw5w-rmc5-f87r.json b/advisories/unreviewed/2025/03/GHSA-pw5w-rmc5-f87r/GHSA-pw5w-rmc5-f87r.json new file mode 100644 index 00000000000..8ca72b16893 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pw5w-rmc5-f87r/GHSA-pw5w-rmc5-f87r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pw5w-rmc5-f87r", + "modified": "2025-03-10T09:31:48Z", + "published": "2025-03-10T09:31:48Z", + "aliases": [ + "CVE-2025-27254" + ], + "details": "Improper Authentication vulnerability in GE Vernova EnerVista UR Setup allows Authentication Bypass. \nThe software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27254" + }, + { + "type": "WEB", + "url": "https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r5j3-c4vg-xf85/GHSA-r5j3-c4vg-xf85.json b/advisories/unreviewed/2025/03/GHSA-r5j3-c4vg-xf85/GHSA-r5j3-c4vg-xf85.json new file mode 100644 index 00000000000..8b26d52d358 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r5j3-c4vg-xf85/GHSA-r5j3-c4vg-xf85.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5j3-c4vg-xf85", + "modified": "2025-03-10T09:31:48Z", + "published": "2025-03-10T09:31:48Z", + "aliases": [ + "CVE-2025-2150" + ], + "details": "The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be executed in the recipient's browser when they view the email.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2150" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10005-05e0f-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10004-99474-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T08:15:11Z" + } +} \ No newline at end of file