A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

We strongly recommend that users with impacted firmware versions update their UR devices to UR firmware version 8.70, released in November 2025, to resolve these vulnerabilities. We also recommend upgrading the EnerVista UR Setup configuration tool to version 8.70 or greater. Enervista UR Setup software is backward compatible, users can upgrade it to version 8.70, independently of upgrading their UR IED to FW v870.


Workaround

As a workaround, GE Vernova recommends having secure infrastructure in place, which can protect the system. We also recommend that customers protect their digital devices using a defense-in-depth strategy. This includes, but is not limited to, placing digital devices inside the control system network security perimeter, access controls, robust network monitoring (such as Intrusion Detection System) and other mitigation techniques in place. Please refer to the product secure deployment guide. It is essential for organizations to prioritize cybersecurity measures, including regular vulnerability assessments and prompt application of security patches.

History

Tue, 10 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
Title Enervista UR Setup Directory Traversal Vulnerability
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GE_Vernova

Published:

Updated: 2026-02-10T20:37:25.289Z

Reserved: 2026-02-02T14:36:44.351Z

Link: CVE-2026-1762

cve-icon Vulnrichment

Updated: 2026-02-10T20:37:20.530Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-10T20:16:52.940

Modified: 2026-02-10T21:51:48.077

Link: CVE-2026-1762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses