VYPR

Vendor CVEs

Ge

All CVEs

134 total · sorted by risk
  • CVE-2021-27448HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).

  • CVE-2019-13559HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instructions immediately available to the end user. The bulk of…

  • CVE-2019-6566HigMay 9, 2019
    risk 0.51cvss 7.8epss 0.00

    GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system.

  • CVE-2019-6564HigMay 9, 2019
    risk 0.51cvss 7.8epss 0.00

    GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

  • CVE-2019-6546HigMay 9, 2019
    risk 0.51cvss 7.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.

  • CVE-2018-10613HigJun 4, 2018
    risk 0.50cvss 7.5epss 0.18

    Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.

  • CVE-2023-5909HigNov 30, 2023
    risk 0.49cvss 7.5epss 0.00

    KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.

  • CVE-2022-46660HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user could alter or write files with full control over the path and content of the file.

  • CVE-2022-46331HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user could possibly delete any file on the system.

  • CVE-2022-43494HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

  • CVE-2022-38469HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

  • CVE-2022-43975HigJan 17, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.

  • CVE-2021-44477HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is…

  • CVE-2021-27422HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

  • CVE-2022-23921HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already…

  • CVE-2022-21798HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.

  • CVE-2019-13524HigJan 16, 2020
    risk 0.49cvss 7.5epss 0.02

    GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a…

  • CVE-2018-19003HigDec 14, 2018
    risk 0.49cvss 7.5epss 0.03

    GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The affected versions of the application have a path traversal…

  • CVE-2017-7908HigOct 2, 2018
    risk 0.49cvss 7.6epss 0.01

    A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.

  • CVE-2018-8867HigMay 18, 2018
    risk 0.49cvss 7.5epss 0.03

    In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could…

  • CVE-2021-31477HigJun 16, 2021
    risk 0.48cvss 7.3epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and…

  • CVE-2018-6021HigMay 9, 2018
    risk 0.48cvss 7.4epss 0.01

    Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution.

  • CVE-2020-16244HigSep 23, 2020
    risk 0.47cvss 7.2epss 0.01

    GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all…

  • CVE-2016-0862MedFeb 5, 2016
    risk 0.46cvss 6.5epss 0.10

    General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

  • CVE-2020-6992MedApr 15, 2020
    risk 0.44cvss 6.7epss 0.00

    A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only…

  • CVE-2020-6977MedFeb 20, 2020
    risk 0.44cvss 6.8epss 0.00

    A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include…

  • CVE-2017-12732MedOct 5, 2017
    risk 0.44cvss 6.8epss 0.01

    A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution.

  • CVE-2016-9360MedFeb 13, 2017
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if…

  • CVE-2023-3463MedJul 19, 2023
    risk 0.43cvss 6.6epss 0.00

    All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free,…

  • CVE-2023-1552MedApr 11, 2023
    risk 0.42cvss 6.4epss 0.00

    ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an…

  • CVE-2018-6020MedMay 9, 2018
    risk 0.42cvss 6.5epss 0.01

    In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.

  • CVE-2016-5787MedJul 15, 2016
    risk 0.41cvss 6.3epss 0.00

    General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.

  • CVE-2020-16246MedOct 20, 2020
    risk 0.40cvss 6.1epss 0.01

    The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be…

  • CVE-2020-16242MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

  • CVE-2020-36548MedJun 17, 2022
    risk 0.38cvss 5.9epss 0.00

    A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.

  • CVE-2020-36547MedJun 17, 2022
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.

  • CVE-2019-18243MedFeb 18, 2021
    risk 0.36cvss 5.5epss 0.00

    HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.

  • CVE-2019-18255MedFeb 18, 2021
    risk 0.36cvss 5.5epss 0.00

    HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

  • CVE-2019-6544MedMay 9, 2019
    risk 0.36cvss 5.6epss 0.01

    GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is…

  • CVE-2021-27424MedMar 23, 2022
    risk 0.35cvss 5.3epss 0.01

    GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.

  • CVE-2021-27420MedMar 23, 2022
    risk 0.35cvss 5.3epss 0.01

    GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is…

  • CVE-2020-25193MedMar 18, 2022
    risk 0.35cvss 5.3epss 0.01

    By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.

  • CVE-2020-16240MedSep 23, 2020
    risk 0.35cvss 5.3epss 0.01

    GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have access to such functionality. An attacker can download…

  • CVE-2019-18267MedDec 18, 2019
    risk 0.35cvss 5.4epss 0.02

    An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a…

  • CVE-2019-10966MedJul 10, 2019
    risk 0.35cvss 5.3epss 0.01

    In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

  • CVE-2015-3976MedAug 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.

  • CVE-2023-0898MedNov 7, 2023
    risk 0.34cvss 5.3epss 0.00

    General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.

  • CVE-2021-27418MedMar 23, 2022
    risk 0.34cvss 5.3epss 0.01

    GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server…

  • CVE-2022-37953MedAug 25, 2022
    risk 0.31cvss 4.7epss 0.00

    An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker to compromise a victim's browser/session. WorkstationST is only deployed in specific, controlled environments rendering attack…

  • CVE-2022-37952MedAug 25, 2022
    risk 0.31cvss 4.7epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specific, controlled environments rendering attack complexity…