Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions.
Advisories

No advisories yet.

Fixes

Solution

GE Vernova recommends that users upgrade to the appropriate non-affected version listed above in accordance with their use case and architecture, as this is the most complete method to address the Vulnerability. Also, users are strongly advised to follow the SDG instructions. The complete SDG can be found in the Smallworld Documentation. To obtain the latest version of SWMFS, please contact your local support representative at Customer Center.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions.
Title Smallworld SWMFS Arbitrary File Ops
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GE_Vernova

Published:

Updated: 2025-11-07T19:17:44.314Z

Reserved: 2025-07-16T16:37:57.358Z

Link: CVE-2025-7719

cve-icon Vulnrichment

Updated: 2025-11-07T19:17:41.255Z

cve-icon NVD

Status : Received

Published: 2025-11-07T17:15:47.990

Modified: 2025-11-07T17:15:47.990

Link: CVE-2025-7719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.