Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Industrial Gateway Server HIGH 7.5
CVE-2023-5909

KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

Fix: after 7.614
Fix from $1,950 2023-11-30
Industrial Gateway Server CRITICAL 9.1
CVE-2023-5908

KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

Fix: after 7.614
Fix from $2,300 2023-11-30
Micom S1 Agile HIGH 7.3
CVE-2023-0898

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the applicat…

Mitigation only
Fix from $1,950 2023-11-07
Cimplicity HIGH 7.8
CVE-2023-4487

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected …

Mitigation only
Fix from $1,950 2023-09-05
Cimplicity CRITICAL 9.8
CVE-2023-3463

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory c…

Mitigation only
Fix from $2,300 2023-07-19
Toolboxst HIGH 7.8
CVE-2023-1552

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social…

Fix: 7.10+
Fix from $1,950 2023-04-11
Industrial Gateway Server CRITICAL 9.8
CVE-2022-2825

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is n…

Fix: 1.4 / 6.12+
Fix from $2,300 2023-03-29
Industrial Gateway Server CRITICAL 9.1
CVE-2022-2848

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is n…

Fix: 1.4 / 6.12+
Fix from $2,300 2023-03-29
Ifix CRITICAL 9.8
CVE-2023-0598

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att…

Mitigation only
Fix from $2,300 2023-03-16
Digital Industrial Gateway Server CRITICAL 9.8
CVE-2023-0754

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute ar…

Fix: after 7.612
Fix from $2,300 2023-02-23
Digital Industrial Gateway Server CRITICAL 9.8
CVE-2023-0755EPSS 12%

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute…

Fix: after 7.612
Fix from $2,300 2023-02-23
Proficy Historian CRITICAL 9.8
CVE-2022-46732

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

Fix: 2023+
Fix from $2,300 2023-01-18
Proficy Historian HIGH 8.1
CVE-2022-46331

An unauthorized user could possibly delete any file on the system.

Fix: 2023+
Fix from $1,950 2023-01-18
Proficy Historian MEDIUM 6.5
CVE-2022-43494

An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

Fix: 2023+
Fix from $1,600 2023-01-18
Proficy Historian MEDIUM 6.5
CVE-2022-46660

An unauthorized user could alter or write files with full control over the path and content of the file.

Fix: 2023+
Fix from $1,600 2023-01-18
Proficy Historian HIGH 7.5
CVE-2022-38469

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

Fix: 2023+
Fix from $1,950 2023-01-18
Ms 3000 Firmware CRITICAL 9.8
CVE-2022-43977

An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) l…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $2,300 2023-01-17
Ms 3000 Firmware CRITICAL 9.8
CVE-2022-43976

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possibl…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $2,300 2023-01-17
Ms 3000 Firmware HIGH 7.5
CVE-2022-43975

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server a…

Fix: 3.7.6.25p0_3.2.2.17p0_4.7p0+
Fix from $1,950 2023-01-17
Inet 900 Firmware CRITICAL 9.8
CVE-2022-24119

Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This af…

Fix: 1.2.6 / 2.0.16+
Fix from $2,300 2022-12-26
Inet 900 Firmware CRITICAL 9.1
CVE-2022-24118

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This aff…

Fix: 1.2.6 / 2.0.16+
Fix from $2,300 2022-12-26
Inet 900 Firmware CRITICAL 9.8
CVE-2022-24116

Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

Fix: 1.2.6 / 2.0.16+
Fix from $2,300 2022-12-26
Inet 900 Firmware CRITICAL 9.8
CVE-2022-24117

Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD befor…

Fix: 1.2.6 / 2.0.16+
Fix from $2,300 2022-12-26
Cimplicity HIGH 7.8
CVE-2022-3092

GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.

Fix: after 2022
Fix from $1,950 2022-12-08
Cimplicity HIGH 7.8
CVE-2022-3084

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, whi…

Fix: after 2022
Fix from $1,950 2022-12-08
Cimplicity HIGH 7.8
CVE-2022-2952

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, w…

Fix: after 2022
Fix from $1,950 2022-12-07
Cimplicity HIGH 7.8
CVE-2022-2002

GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, w…

Fix: after 2022
Fix from $1,950 2022-12-07
Cimplicity HIGH 7.8
CVE-2022-2948

GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

Fix: after 2022
Fix from $1,950 2022-12-07
Workstationst MEDIUM 6.1
CVE-2022-37952

A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to c…

Fix: 07.09.15+
Fix from $1,600 2022-08-25
Workstationst MEDIUM 6.1
CVE-2022-37953

An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker…

Fix: 07.09.15+
Fix from $1,600 2022-08-25