VYPR
Vendor

Ge

Products
161
CVEs
134
Across products
193
Status
Private

Products

161
View all 161 products →

Recent CVEs

134
View all 134 CVEs →
  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2020-27265CriJan 14, 2021
    risk 0.65cvss 9.8epss 0.10

    KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server:…

  • CVE-2016-5788CriNov 25, 2016
    risk 0.65cvss 10.0epss 0.02

    General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors.

  • CVE-2022-2825CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue…

  • CVE-2023-0754CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.03

    The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2022-46732CriJan 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

  • CVE-2022-43977CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.

  • CVE-2022-43976CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.

  • CVE-2022-24119CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.

  • CVE-2022-24117CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

  • CVE-2022-24116CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

  • CVE-2021-27428CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade…

  • CVE-2021-27426CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

  • CVE-2020-25197CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.

  • CVE-2021-27440CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.01

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

  • CVE-2020-12017CriJun 2, 2020
    risk 0.64cvss 9.8epss 0.02

    GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious impact. The vulnerability may allow an unauthenticated…

  • CVE-2019-6548CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

  • CVE-2018-10611CriJun 4, 2018
    risk 0.64cvss 9.8epss 0.05

    Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.

  • CVE-2017-14008CriMar 20, 2018
    risk 0.64cvss 9.8epss 0.03

    GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.

  • CVE-2017-14006CriMar 20, 2018
    risk 0.64cvss 9.8epss 0.02

    GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the…