Ge
ge
128 CVEs • 227 products
Products (227)
Click to collapseToggle
Products (227)
Click to collapse
CVEs (128)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreJun 17, 2026 Nov 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
|
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreJun 17, 2026 Nov 30, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
|
General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.
|
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control...Show more |
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issue...Show more |
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a T...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server Kepserver EnterpriseKepware Kepserverex+5 moreJun 17, 2026 Mar 29, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server Kepserver EnterpriseKepware Kepserverex+5 moreJun 17, 2026 Mar 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more |
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web serv...Show more |
3Ge PtcRockwellautomation9Digital Industrial Gateway Server Kepserver EnterpriseKepware Server+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
|
3Ge PtcRockwellautomation9Digital Industrial Gateway Server Kepserver EnterpriseKepware Server+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
The affected products are vulnerable to an integer
overflow or wraparound, which could allow an attacker to crash the server and remotely
execute arbitrary code.
|
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. |
An unauthorized user could alter or write files with full control over the path and content of the file.
|
An unauthorized user could possibly delete any file on the system.
|
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
|
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
|
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control. |
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without a...Show more |
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory trave...Show more |
1Ge 8Inet 900 Firmware Inet Ii 900 FirmwareSd1 Firmware+5 moreJun 17, 2026 Dec 26, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0. |