CVE-2025-3222 Details
Description
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
A vulnerability allowing authentication abuse has been identified in GE Vernova Smallworld Master File Server (SWMFS) versions 5.3.3 and prior for Linux, and 5.3.4 and prior for Windows. This improper authentication vulnerability could be exploited to bypass authentication and potentially execute elevated commands. The issue affects Smallworld deployments not using Desktop authentication via an authentication server, such as UAA or Zitadel, and not following the secure deployment guidelines.
GE Vernova recommends users upgrade to Smallworld version 5.3.4 for Linux SWMFS users and 5.3.5 for Windows SWMFS users. Users are also advised to follow the Secure Deployment Guidelines. The latest version of SWMFS can be obtained by contacting a local support representative at the Customer Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 7, 2025CISA-ADP
Assessed Nov 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.gevernova.com/content/dam/cyber_security/global/en_US/pdfs/SecurityAdvisory_ImproperAuthentication_SWMFS.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GE Vernova Smallworld | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | New CVE Received | [email protected] |
Volerion