Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Micom S1 Agile HIGH 7.3
CVE-2023-0898

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the applicat…

Mitigation only
Fix from $1,950 2023-11-07
Cimplicity HIGH 7.8
CVE-2023-4487

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected …

Mitigation only
Fix from $1,950 2023-09-05
Cimplicity CRITICAL 9.8
CVE-2023-3463

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory c…

Mitigation only
Fix from $2,300 2023-07-19
Ifix CRITICAL 9.8
CVE-2023-0598

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an att…

Mitigation only
Fix from $2,300 2023-03-16
Voluson S8 Firmware HIGH 7.8
CVE-2020-36549

A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might intr…

Mitigation only
Fix from $1,950 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36547

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credenti…

Mitigation only
Fix from $1,950 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36548

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The mani…

Mitigation only
Fix from $1,950 2022-06-17
Ur Bootloader Binary MEDIUM 6.8
CVE-2021-27430

GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED ca…

Mitigation only
Fix from $1,600 2022-03-23
Cimplicity CRITICAL 9.8
CVE-2022-21798

The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used …

Mitigation only
Fix from $2,300 2022-02-25
Reason Rpv311 Firmware HIGH 7.3
CVE-2021-31477

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not requi…

Mitigation only
Fix from $1,950 2021-06-16
Mark Vie Control System HIGH 8.8
CVE-2019-13554

GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. G…

Mitigation only
Fix from $1,950 2020-04-07
Mark Vie Controll System HIGH 7.8
CVE-2019-13559

GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application…

Mitigation only
Fix from $1,950 2020-04-07
Vivid E95 Firmware MEDIUM 6.8
CVE-2020-6977

A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow …

Mitigation only
Fix from $1,600 2020-02-20
D20me Firmware HIGH 7.5
CVE-2012-6663EPSS 9%

General Electric D20ME devices are not properly configured and reveal plaintext passwords.

No fix yet
Fix from $1,950 2020-01-23
Aestiva 7100 Firmware MEDIUM 5.3
CVE-2019-10966

In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to…

Mitigation only
Fix from $1,600 2019-07-10
Cimplicity CRITICAL 9.1
CVE-2018-15362

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

Mitigation only
Fix from $2,300 2018-12-07
Infinia Hawkeye 4 Firmware CRITICAL 9.8
CVE-2017-14002

GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ…

Mitigation only
Fix from $2,300 2018-03-20
Gemnet License Server CRITICAL 9.8
CVE-2017-14004

GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation …

Mitigation only
Fix from $2,300 2018-03-20
Xeleris CRITICAL 9.8
CVE-2017-14006

GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti…

Mitigation only
Fix from $2,300 2018-03-20
Centricity Pacs Ra1000 CRITICAL 9.8
CVE-2017-14008

GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf…

Mitigation only
Fix from $2,300 2018-03-20
Bently Nevada 3500\/22m Usb Firmware CRITICAL 10.0
CVE-2016-5788

General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier fo…

Mitigation only
Fix from $2,300 2016-11-25
Hydran M2 MEDIUM 5.0
CVE-2014-5409

The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initia…

Mitigation only
Fix from $1,600 2015-03-14
12400 Level Transmitter Device Type Manager MEDIUM 5.0
CVE-2014-9203

Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, …

Mitigation only
Fix from $1,600 2015-02-07
Intelligent Platforms Proficy Hmi\/scada Cimplicity HIGH 9.3
CVE-2013-2785

Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, …

Mitigation only
Fix from $1,950 2013-07-31
Intelligent Platforms Proficy Hmi\/scada Cimplicity HIGH 9.3
CVE-2013-0654

CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote …

Mitigation only
Fix from $1,950 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0651

The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0652

GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote a…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3010EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3021EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01
Intelligent Platforms Proficy Real Time Information Portal HIGH 10.0
CVE-2012-3026EPSS 5%

rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attack…

Mitigation only
Fix from $1,950 2012-11-01