CVE-2025-9038 Details
Description
Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.
A privilege escalation vulnerability has been identified in GE Vernova S1 Agile Configuration Software for MiCOM P40 relays, affecting all versions prior to 3.1.1. This vulnerability allows a malicious user with basic privileges on the workstation to replace a legitimate executable file with a malicious one. Upon restarting the computer, the attacker's code could be executed, potentially granting them administrator privileges on the machine.
Users are advised to upgrade to GE Vernova S1 Agile version 3.1.1, released in January 2025. For additional support, contact the GE Vernova global support team or the GE Product Security Incident Response Team (PSIRT).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2025CISA-ADP
Assessed Sep 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.gevernova.com/grid-solutions/sites/default/files/resources/products/support/ges-2025-001.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GE Vernova S1 Agile | <= 3.1.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2025 | New CVE Received | [email protected] |
Volerion