Metrics
Affected Vendors & Products
No advisories yet.
Solution
We strongly recommend that users with impacted firmware versions update their UR devices to UR firmware version 8.70, released in November 2025, to resolve these vulnerabilities. We also recommend upgrading the EnerVista UR Setup configuration tool to version 8.70 or greater. Enervista UR Setup software is backward compatible, users can upgrade it to version 8.70, independently of upgrading their UR IED to FW v870.
Workaround
As a workaround, GE Vernova recommends having secure infrastructure in place, which can protect the system. We also recommend that customers protect their digital devices using a defense-in-depth strategy. This includes, but is not limited to, placing digital devices inside the control system network security perimeter, access controls, robust network monitoring (such as Intrusion Detection System) and other mitigation techniques in place. Please refer to the product secure deployment guide. It is essential for organizations to prioritize cybersecurity measures, including regular vulnerability assessments and prompt application of security patches.
Tue, 10 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions. | |
| Title | Enervista UR Setup Directory Traversal Vulnerability | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GE_Vernova
Published:
Updated: 2026-02-10T20:37:25.289Z
Reserved: 2026-02-02T14:36:44.351Z
Link: CVE-2026-1762
Updated: 2026-02-10T20:37:20.530Z
Status : Awaiting Analysis
Published: 2026-02-10T20:16:52.940
Modified: 2026-02-10T21:51:48.077
Link: CVE-2026-1762
No data.
OpenCVE Enrichment
No data.