Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
CVE ID: CVE-2025-27255
CVSS Base Severity: HIGH
CVSS Base Score: 8.0
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Vendor: GE Vernova
Product: EnerVista UR Setup
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 1.95% (scored less or equal to compared to others)
EPSS Date: 2025-04-08 (when was this score calculated)