Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Asset Performance Management Classic MEDIUM 5.3
CVE-2020-16240

GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in…

Fix: after 4.4
Fix from $1,600 2020-09-23
Rt430 Firmware CRITICAL 9.8
CVE-2020-12017

GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application …

Fix: 08a05+
Fix from $2,300 2020-06-02
Cimplicity MEDIUM 6.7
CVE-2020-6992

A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vul…

Fix: after 10.0
Fix from $1,600 2020-04-15
Mark Vie Control System HIGH 8.8
CVE-2019-13554

GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. G…

Mitigation only
Fix from $1,950 2020-04-07
Mark Vie Controll System HIGH 7.8
CVE-2019-13559

GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application…

Mitigation only
Fix from $1,950 2020-04-07
Vivid E95 Firmware MEDIUM 6.8
CVE-2020-6977

A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow …

Mitigation only
Fix from $1,600 2020-02-20
D20me Firmware HIGH 7.5
CVE-2012-6663EPSS 9%

General Electric D20ME devices are not properly configured and reveal plaintext passwords.

No fix yet
Fix from $1,950 2020-01-23
S2020 Firmware MEDIUM 5.4
CVE-2019-18267

An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Ja…

Fix: after 07a03
Fix from $1,600 2019-12-18
Aestiva 7100 Firmware MEDIUM 5.3
CVE-2019-10966

In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to…

Mitigation only
Fix from $1,600 2019-07-10
Ge Communicator CRITICAL 9.8
CVE-2019-6548

GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database.…

Fix: 4.0.517+
Fix from $2,300 2019-05-09
Ge Communicator HIGH 7.8
CVE-2019-6564

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which …

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Ge Communicator HIGH 7.8
CVE-2019-6566

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could all…

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Ge Communicator HIGH 7.8
CVE-2019-6546

GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may al…

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Ge Communicator MEDIUM 5.6
CVE-2019-6544

GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain a…

Fix: 4.0.517+
Fix from $1,600 2019-05-09
Ex2100e Firmware HIGH 7.5
CVE-2018-19003

GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions pr…

Fix: 04.09.00c+
Fix from $1,950 2018-12-14
Cimplicity CRITICAL 9.1
CVE-2018-15362

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

Mitigation only
Fix from $2,300 2018-12-07
Mds Pulsenet CRITICAL 9.8
CVE-2018-10611

Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unaut…

Fix: after 3.2.1
Fix from $2,300 2018-06-04
Mds Pulsenet HIGH 8.1
CVE-2018-10615

Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host pl…

Fix: after 3.2.1
Fix from $1,950 2018-06-04
Mds Pulsenet HIGH 7.5
CVE-2018-10613EPSS 18%

Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS Pulse…

Fix: after 3.2.1
Fix from $1,950 2018-06-04
Pacsystems Rx3i Cpe305 Firmware HIGH 7.5
CVE-2018-8867

In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP …

Fix: after 9.30
Fix from $1,950 2018-05-18
Infinia Hawkeye 4 Firmware CRITICAL 9.8
CVE-2017-14002

GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ…

Mitigation only
Fix from $2,300 2018-03-20
Gemnet License Server CRITICAL 9.8
CVE-2017-14004

GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation …

Mitigation only
Fix from $2,300 2018-03-20
Xeleris CRITICAL 9.8
CVE-2017-14006

GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti…

Mitigation only
Fix from $2,300 2018-03-20
Centricity Pacs Ra1000 CRITICAL 9.8
CVE-2017-14008

GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf…

Mitigation only
Fix from $2,300 2018-03-20
D60 Line Distance Relay Firmware CRITICAL 9.8
CVE-2018-5473EPSS 6%

An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmwar…

Fix: after 7.11
Fix from $2,300 2018-02-19
D60 Line Distance Relay Firmware CRITICAL 9.8
CVE-2018-5475

A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-base…

Fix: after 7.11
Fix from $2,300 2018-02-19
Intelligent Platforms Proficy Hmi\/scada Cimplicity MEDIUM 6.8
CVE-2017-12732

A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet len…

Fix: after 9.0
Fix from $1,600 2017-10-05
Multilink Ml810 Firmware MEDIUM 5.4
CVE-2015-3976

Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1…

Fix: after 5.2.0
Fix from $1,600 2017-08-28
Multilin Sr 750 Feeder Protection Relay Firmware CRITICAL 9.8
CVE-2017-7905

A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to V…

Fix: after 6.0
Fix from $2,300 2017-06-30
Cimplicity MEDIUM 6.7
CVE-2016-9360

An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9…

Fix: after 9.0
Fix from $1,600 2017-02-13