Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
Advisories

No advisories yet.

Fixes

Solution

GE Vernova recommends that users upgrade to the appropriate non-affected version listed above in accordance with their use case and architecture as this is the most complete method to address the Vulnerability. Also, users are strongly advised to follow the SDG instructions. The complete SDG can be found in the Smallworld Documentation. To obtain the latest version of SWMFS, please contact your local support representative at Customer Center.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
Title Smallworld SWMFS Improper Authentication
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GE_Vernova

Published:

Updated: 2025-11-07T19:17:12.529Z

Reserved: 2025-04-03T13:47:11.155Z

Link: CVE-2025-3222

cve-icon Vulnrichment

Updated: 2025-11-07T19:17:09.727Z

cve-icon NVD

Status : Received

Published: 2025-11-07T17:15:47.500

Modified: 2025-11-07T17:15:47.500

Link: CVE-2025-3222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.