Skip to main content

Vendor archive

ge CVEs

Beta · best-effort

128 CVEs tagged to vendor ge48 Critical, 40 High, 40 Medium, 0 Low, 0 Unrated.

CVE-2021-27448

Published Mar 25, 2021

A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18243

Published Feb 18, 2021

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18255

Published Feb 18, 2021

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27267

Published Jan 14, 2021

KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer En…

CVSS 9.1 · Critical

CVE-2020-27265

Published Jan 14, 2021

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer En…

CVSS 9.8 · Critical

CVE-2020-27263

Published Jan 14, 2021

KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer En…

CVSS 9.1 · Critical

CVE-2020-16244

Published Sep 23, 2020

GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16240

Published Sep 23, 2020

GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (J…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6992

Published Apr 15, 2020

A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adve…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13559

Published Apr 7, 2020

GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13554

Published Apr 7, 2020

GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. GE recommends that users disabl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6566

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain adminis…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6564

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6548

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6546

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6544

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which m…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 51-75 of 128 CVEsPage 3 of 6