Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.
Fixes

Solution

To resolve this issue and enhance security, during the S1 Agile application installation, we ensure only privileged users can access various folders used by the S1 Agile application. This ensures that S1 Agile files can not be edited or replaced by users without sufficient privileges on that computer. We would like to assert that this attack, if successful, can give “Administrator” privileges to the attacker on the computer, but the configured IEDs will not see any impact in their configuration or functionality. The RBAC (‘Role-Based Access Control’) on the IED remains unimpacted. We strongly recommend customers to upgrade to the latest software version available. Software version 3.1.1 is released for customer usage in January 2025.


Workaround

As a workaround, GE Vernova recommends having sufficient security controls in place on the workstation where S1 Agile software is installed. This will ensure the attacker’s remote connection to the computer is not feasible. Harden the computer on which S1 Agile is installed. The product deployment guide can be used to understand the guidelines around how the product can be deployed in the end user’s environment.

History

Mon, 22 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.
Title S1 Agile Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GE_Vernova

Published:

Updated: 2025-09-22T14:49:38.805Z

Reserved: 2025-08-14T13:30:30.722Z

Link: CVE-2025-9038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-22T15:15:40.423

Modified: 2025-09-22T15:15:40.423

Link: CVE-2025-9038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.