Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Voluson S8 Firmware HIGH 7.8
CVE-2020-36549

A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might intr…

Mitigation only
Fix from $1,950 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36547

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credenti…

Mitigation only
Fix from $1,950 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36548

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The mani…

Mitigation only
Fix from $1,950 2022-06-17
Toolboxst HIGH 7.5
CVE-2021-44477

GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that cou…

Fix: 07.09.07c+
Fix from $1,950 2022-03-25
Multilin B30 Firmware CRITICAL 9.8
CVE-2021-27426

GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for…

Fix: 8.10+
Fix from $2,300 2022-03-23
Multilin B30 Firmware CRITICAL 9.8
CVE-2021-27428

GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup t…

Fix: 8.10+
Fix from $2,300 2022-03-23
Multilin B30 Firmware HIGH 7.5
CVE-2021-27422

GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure wi…

Fix: 8.10+
Fix from $1,950 2022-03-23
Ur Bootloader Binary MEDIUM 6.8
CVE-2021-27430

GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED ca…

Mitigation only
Fix from $1,600 2022-03-23
Multilin B30 Firmware MEDIUM 6.1
CVE-2021-27418

GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making …

Fix: 8.10+
Fix from $1,600 2022-03-23
Multilin B30 Firmware MEDIUM 5.3
CVE-2021-27420

GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server…

Fix: 8.10+
Fix from $1,600 2022-03-23
Multilin B30 Firmware MEDIUM 5.3
CVE-2021-27424

GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MO…

Fix: 8.10+
Fix from $1,600 2022-03-23
Rt430 Firmware HIGH 8.8
CVE-2020-25197

A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A0…

Fix: 08a06+
Fix from $1,950 2022-03-18
Rt430 Firmware MEDIUM 5.3
CVE-2020-25193

By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, atta…

Fix: 08a06+
Fix from $1,600 2022-03-18
Proficy Cimplicitiy HIGH 7.8
CVE-2022-23921

Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is on…

Fix: after 11.1
Fix from $1,950 2022-02-25
Cimplicity CRITICAL 9.8
CVE-2022-21798

The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used …

Mitigation only
Fix from $2,300 2022-02-25
Reason Rpv311 Firmware HIGH 7.3
CVE-2021-31477

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not requi…

Mitigation only
Fix from $1,950 2021-06-16
Mu320e Firmware HIGH 7.8
CVE-2021-27448

A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior …

Fix: 04a00.1+
Fix from $1,950 2021-03-25
Mu320e Firmware HIGH 7.8
CVE-2021-27450

SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead t…

Fix: 04a00.1+
Fix from $1,950 2021-03-25
Mu320e Firmware HIGH 7.8
CVE-2021-27452

The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on th…

Fix: 04a00.1+
Fix from $1,950 2021-03-25
Reason Dr60 Firmware HIGH 7.8
CVE-2021-27454

The software performs an operation at a privilege level higher than the minimum level required, which creates new weaknesses or amplifies the consequ…

Fix: 02a04.1+
Fix from $1,950 2021-03-25
Reason Dr60 Firmware CRITICAL 9.8
CVE-2021-27440

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re…

Fix: 02a04.1+
Fix from $2,300 2021-03-25
Reason Dr60 Firmware HIGH 8.8
CVE-2021-27438

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re…

Fix: 02a04.1+
Fix from $1,950 2021-03-25
Ifix MEDIUM 5.5
CVE-2019-18243

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may al…

Fix: after 6.1
Fix from $1,600 2021-02-18
Ifix MEDIUM 5.5
CVE-2019-18255

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may…

Fix: after 6.1
Fix from $1,600 2021-02-18
Industrial Gateway Server CRITICAL 9.8
CVE-2020-27265EPSS 10%

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Ro…

Fix: after 6.9
Fix from $2,300 2021-01-14
Industrial Gateway Server CRITICAL 9.1
CVE-2020-27263

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Ro…

Fix: after 6.9
Fix from $2,300 2021-01-14
Industrial Gateway Server CRITICAL 9.1
CVE-2020-27267

KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Ro…

Fix: after 6.9
Fix from $2,300 2021-01-14
S2020 Firmware MEDIUM 6.1
CVE-2020-16246

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link o…

Fix: 07a06+
Fix from $1,600 2020-10-20
S2020 Firmware MEDIUM 6.1
CVE-2020-16242

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into perf…

Fix: 07a06+
Fix from $1,600 2020-09-25
Asset Performance Management Classic HIGH 7.2
CVE-2020-16244

GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This des…

Fix: after 4.4
Fix from $1,950 2020-09-23