Skip to main content

Vendor archive

ge CVEs

Beta · best-effort

128 CVEs tagged to vendor ge48 Critical, 40 High, 40 Medium, 0 Low, 0 Unrated.

CVE-2022-3084

Published Dec 8, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2952

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2948

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2002

Published Dec 7, 2022

GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37953

Published Aug 25, 2022

An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker to compromise a victim's brow…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37952

Published Aug 25, 2022

A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser.…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36549

Published Jun 17, 2022

A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might introduce an excessive attack surf…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36548

Published Jun 17, 2022

A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper aut…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36547

Published Jun 17, 2022

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a re…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44477

Published Mar 25, 2022

GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27430

Published Mar 23, 2022

GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23921

Published Feb 25, 2022

Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker ha…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-21798

Published Feb 25, 2022

The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-31477

Published Jun 16, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerabil…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27452

Published Mar 25, 2021

The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware version…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27450

Published Mar 25, 2021

SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol strength, which could lead to additional misconfiguration…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 128 CVEsPage 2 of 6