CVE-2025-3223

medium

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST on Windows (EGD Configuration Server modules) allows Path Traversal.This issue affects WorkstationST: WorkstationST V07.10.10C and earlier.

References

https://www.gevernova.com/content/dam/cyber_security/global/en_US/pdfs/2024-09-24_EGD_Config_Server_File_Overwrite.pdf

Details

Source: Mitre, NVD

Published: 2025-05-19

Updated: 2026-04-15

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:A/AC:H/Au:S/C:P/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 5.9

Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L

Severity: Medium

EPSS

EPSS: 0.0002