Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bently Nevada 3500\/22m Usb Firmware CRITICAL 10.0
CVE-2016-5788

General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier fo…

Mitigation only
Fix from $2,300 2016-11-25
Cimplicity MEDIUM 6.3
CVE-2016-5787

General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service…

Fix: 8.2+
Fix from $1,600 2016-07-15
Multilink Firmware CRITICAL 9.8
CVE-2016-2310

General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with fir…

Fix: after 5.5.0
Fix from $2,300 2016-06-09
Snmp\/web Adapter Firmware MEDIUM 6.5
CVE-2016-0862EPSS 10%

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive…

Fix: after 4.7
Fix from $1,600 2016-02-05
Ups Snmp Web Adapter Firmware HIGH 8.8
CVE-2016-0861EPSS 14%

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrar…

Fix: after 4.7
Fix from $1,950 2016-02-05
Mds Pulsenet HIGH 10.0
CVE-2015-6459

Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise be…

Fix: after 3.1.3
Fix from $1,950 2015-09-18
Mds Pulsenet HIGH 9.0
CVE-2015-6456

GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attacke…

Fix: after 3.1.3
Fix from $1,950 2015-09-18
Hydran M2 MEDIUM 5.0
CVE-2014-5409

The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initia…

Mitigation only
Fix from $1,600 2015-03-14
12400 Level Transmitter Device Type Manager MEDIUM 5.0
CVE-2014-9203

Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, …

Mitigation only
Fix from $1,600 2015-02-07
Multilink Ml3100 Firmware MEDIUM 5.0
CVE-2014-5419

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…

Fix: after 5.2.0
Fix from $1,600 2015-01-17
Multilink Ml810 Firmware HIGH 7.8
CVE-2014-5418

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…

Fix: after 5.2.0
Fix from $1,950 2015-01-17
Intelligent Platforms Proficy Hmi\/scada Cimplicity MEDIUM 6.9
CVE-2014-2355

The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted…

Fix: after 8.2
Fix from $1,600 2015-01-17
Intelligent Platforms Proficy Hmi\%2fscada Cimplicity HIGH 7.5
CVE-2014-0750EPSS 70%

Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8…

Fix: after 8.2
Fix from $1,950 2014-01-25
Intelligent Platforms Proficy Hmi\%2fscada Cimplicity HIGH 7.5
CVE-2014-0751

The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the …

Fix: after 8.2
Fix from $1,950 2014-01-25
Intelligent Platforms Proficy Hmi\/scada Cimplicity HIGH 9.3
CVE-2013-2785

Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, …

Mitigation only
Fix from $1,950 2013-07-31
Intelligent Platforms Proficy Hmi\/scada Cimplicity HIGH 9.3
CVE-2013-0654

CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote …

Mitigation only
Fix from $1,950 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0651

The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0652

GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote a…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3010EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3021EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3026EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Batch Execution HIGH 9.3
CVE-2012-2516EPSS 40%

An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1…

Mitigation only
Fix from $1,950 2012-07-05
Intelligent Platforms Proficy Historian HIGH 10.0
CVE-2012-0229

The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory …

Fix: after 4.5
Fix from $1,950 2012-03-15
Intelligent Platforms Proficy Plant Applications HIGH 10.0
CVE-2012-0230EPSS 9%

PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers to cause …

Fix: after 5.0
Fix from $1,950 2012-03-15
Intelligent Platforms Proficy Plant Applications HIGH 10.0
CVE-2012-0231EPSS 7%

PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers…

Fix: after 5.0
Fix from $1,950 2012-03-15
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 6.4
CVE-2012-0232

Directory traversal vulnerability in rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6…

Mitigation only
Fix from $1,600 2012-03-15
Intelligent Platforms Proficy Historian HIGH 10.0
CVE-2011-1918EPSS 6%

Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 al…

Fix: after 3.5
Fix from $1,950 2011-11-02
Intelligent Platforms Proficy Historian HIGH 10.0
CVE-2011-1919

Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote at…

Fix: after 4.4.1
Fix from $1,950 2011-11-02
Proficy Real Time Information Portal CRITICAL 9.8
CVE-2008-0174

GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encod…

Fix: after 2.6
Fix from $2,300 2008-01-29