Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2020-16240 GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in… Asset Performance Management Classic after 4.4 Fix from $1,6002020-09-23 CRITICAL 9.8 CVE-2020-12017 GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application … Rt430 Firmware 08a05+ Fix from $2,3002020-06-02 MEDIUM 6.7 CVE-2020-6992 A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vul… Cimplicity after 10.0 Fix from $1,6002020-04-15 HIGH 8.8 CVE-2019-13554 GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. G… Mark Vie Control System Mitigation only Fix from $1,9502020-04-07 HIGH 7.8 CVE-2019-13559 GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application… Mark Vie Controll System Mitigation only Fix from $1,9502020-04-07 MEDIUM 6.8 CVE-2020-6977 A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow … Vivid E95 Firmware Mitigation only Fix from $1,6002020-02-20 HIGH 7.5 CVE-2012-6663EPSS 9% General Electric D20ME devices are not properly configured and reveal plaintext passwords. D20me Firmware No fix yet Fix from $1,9502020-01-23 MEDIUM 5.4 CVE-2019-18267 An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Ja… S2020 Firmware after 07a03 Fix from $1,6002019-12-18 MEDIUM 5.3 CVE-2019-10966 In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to… Aestiva 7100 Firmware Mitigation only Fix from $1,6002019-07-10 CRITICAL 9.8 CVE-2019-6548 GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database.… Ge Communicator 4.0.517+ Fix from $2,3002019-05-09 HIGH 7.8 CVE-2019-6564 GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which … Ge Communicator 4.0.517+ Fix from $1,9502019-05-09 HIGH 7.8 CVE-2019-6566 GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could all… Ge Communicator 4.0.517+ Fix from $1,9502019-05-09 HIGH 7.8 CVE-2019-6546 GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may al… Ge Communicator 4.0.517+ Fix from $1,9502019-05-09 MEDIUM 5.6 CVE-2019-6544 GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain a… Ge Communicator 4.0.517+ Fix from $1,6002019-05-09 HIGH 7.5 CVE-2018-19003 GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions pr… Ex2100e Firmware 04.09.00c+ Fix from $1,9502018-12-14 CRITICAL 9.1 CVE-2018-15362 XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0 Cimplicity Mitigation only Fix from $2,3002018-12-07 CRITICAL 9.8 CVE-2018-10611 Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unaut… Mds Pulsenet after 3.2.1 Fix from $2,3002018-06-04 HIGH 8.1 CVE-2018-10615 Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host pl… Mds Pulsenet after 3.2.1 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2018-10613EPSS 18% Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS Pulse… Mds Pulsenet after 3.2.1 Fix from $1,9502018-06-04 HIGH 7.5 CVE-2018-8867 In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP … Pacsystems Rx3i Cpe305 Firmware after 9.30 Fix from $1,9502018-05-18 CRITICAL 9.8 CVE-2017-14002 GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ… Infinia Hawkeye 4 Firmware Mitigation only Fix from $2,3002018-03-20 CRITICAL 9.8 CVE-2017-14004 GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation … Gemnet License Server Mitigation only Fix from $2,3002018-03-20 CRITICAL 9.8 CVE-2017-14006 GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti… Xeleris Mitigation only Fix from $2,3002018-03-20 CRITICAL 9.8 CVE-2017-14008 GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf… Centricity Pacs Ra1000 Mitigation only Fix from $2,3002018-03-20 CRITICAL 9.8 CVE-2018-5473EPSS 6% An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmwar… D60 Line Distance Relay Firmware after 7.11 Fix from $2,3002018-02-19 CRITICAL 9.8 CVE-2018-5475 A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-base… D60 Line Distance Relay Firmware after 7.11 Fix from $2,3002018-02-19 MEDIUM 6.8 CVE-2017-12732 A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet len… Intelligent Platforms Proficy Hmi\/scada Cimplicity after 9.0 Fix from $1,6002017-10-05 MEDIUM 5.4 CVE-2015-3976 Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1… Multilink Ml810 Firmware after 5.2.0 Fix from $1,6002017-08-28 CRITICAL 9.8 CVE-2017-7905 A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to V… Multilin Sr 750 Feeder Protection Relay Firmware after 6.0 Fix from $2,3002017-06-30 MEDIUM 6.7 CVE-2016-9360 An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9… Cimplicity after 9.0 Fix from $1,6002017-02-13