Skip to main content

Vendor archive

ge CVEs

Beta · best-effort

128 CVEs tagged to vendor ge48 Critical, 40 High, 40 Medium, 0 Low, 0 Unrated.

CVE-2023-0898

Published Nov 7, 2023

General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4487

Published Sep 5, 2023

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3463

Published Jul 19, 2023

All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insuff…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1552

Published Apr 11, 2023

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an auth…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2848

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-2825

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-0598

Published Mar 16, 2023

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious conf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0755

Published Feb 23, 2023

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-0754

Published Feb 23, 2023

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-46732

Published Jan 18, 2023

Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-46660

Published Jan 18, 2023

An unauthorized user could alter or write files with full control over the path and content of the file.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-43494

Published Jan 18, 2023

An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38469

Published Jan 18, 2023

An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43977

Published Jan 17, 2023

An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43976

Published Jan 17, 2023

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via program…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43975

Published Jan 17, 2023

An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and conf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24119

Published Dec 26, 2022

Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before…

CVSS 9.8 · Critical

CVE-2022-24118

Published Dec 26, 2022

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8…

CVSS 9.1 · Critical

CVE-2022-24117

Published Dec 26, 2022

Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16,…

CVSS 9.8 · Critical

CVE-2022-3092

Published Dec 8, 2022

GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 128 CVEsPage 1 of 6