Description
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
Published: 2026-02-10
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Directory Traversal leading to file manipulation
Action: Patch
AI Analysis

Impact

The vulnerability in GE Vernova Enervista UR Setup on Windows permits an attacker to manipulate files by exploiting an unchecked path traversal input (CWE-23). This flaw could allow the modification of existing files, the creation of new files, or the deletion of critical configuration data, thereby potentially altering device behavior or gaining unauthorized access to sensitive configuration information. The description does not indicate that an attacker can execute code directly, so the flaw is limited to file manipulation rather than remote code execution.

Affected Systems

Enervista UR Setup software for GE Vernova, versions 8.6 and earlier, runs on Windows platforms. Firmware versions for the associated UR devices older than 8.70 are also affected; upgrading the firmware to 8.70 or later resolves the issue. The newer Enervista UR Setup configuration tool version 8.70, even when installed independently of the firmware, also mitigates the weakness.

Risk and Exploitability

The CVSS score of 2.9 classifies the vulnerability as low severity, and the EPSS score of less than 1% indicates a very small probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector is not explicitly stated in the available information; however, given that the flaw exists within a Windows-based setup utility, it likely requires either local access to the host or remote access to the UR Setup service, potentially under privileged user credentials. Because the vendor recommends defensive controls such as perimeter isolation, access controls, and intrusion detection, the risk can be further reduced by normal network security measures.

Generated by OpenCVE AI on April 16, 2026 at 17:16 UTC.

Remediation

Vendor Solution

We strongly recommend that users with impacted firmware versions update their UR devices to UR firmware version 8.70, released in November 2025, to resolve these vulnerabilities. We also recommend upgrading the EnerVista UR Setup configuration tool to version 8.70 or greater. Enervista UR Setup software is backward compatible, users can upgrade it to version 8.70, independently of upgrading their UR IED to FW v870.


Vendor Workaround

As a workaround, GE Vernova recommends having secure infrastructure in place, which can protect the system. We also recommend that customers protect their digital devices using a defense-in-depth strategy. This includes, but is not limited to, placing digital devices inside the control system network security perimeter, access controls, robust network monitoring (such as Intrusion Detection System) and other mitigation techniques in place. Please refer to the product secure deployment guide. It is essential for organizations to prioritize cybersecurity measures, including regular vulnerability assessments and prompt application of security patches.


OpenCVE Recommended Actions

  • Upgrade Enervista UR Setup to version 8.70 or later
  • Upgrade the UR device firmware to version 8.70 or later
  • Implement defensive network perimeters, enforce strict access controls, and deploy intrusion detection or monitoring to protect the device

Generated by OpenCVE AI on April 16, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 04 Mar 2026 19:30:00 +0000


Wed, 04 Mar 2026 19:00:00 +0000


Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Ge Vernova
Ge Vernova enervista
Vendors & Products Ge Vernova
Ge Vernova enervista

Tue, 10 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
Title Enervista UR Setup Directory Traversal Vulnerability
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Ge Vernova Enervista
cve-icon MITRE

Status: PUBLISHED

Assigner: GE_Vernova

Published:

Updated: 2026-03-04T18:39:46.742Z

Reserved: 2026-02-02T14:36:44.351Z

Link: CVE-2026-1762

cve-icon Vulnrichment

Updated: 2026-02-10T20:37:20.530Z

cve-icon NVD

Status : Deferred

Published: 2026-02-10T20:16:52.940

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T17:30:25Z

Weaknesses