← Back

Ge

ge

128 CVEs • 227 products

Products (227)

Click to collapse
Toggle
Cimplicity
cimplicity
Mds Pulsenet
mds_pulsenet
Ifix
ifix
Sd1 Firmware
sd1_firmware
Sd2 Firmware
sd2_firmware
Sd4 Firmware
sd4_firmware
Sd9 Firmware
sd9_firmware
Toolboxst
toolboxst
Workstationst
workstationst
Hydran M2
hydran_m2
Historian
historian
Xeleris
xeleris

CVEs (128)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
KeepserverexKepserver Enterprise+5 more
Jun 17, 2026
Nov 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
KeepserverexKepserver Enterprise+5 more
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
1Ge
1Micom S1 Agile
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
General Electric MiCOM S1 Agile is vulnerable to an attacker achieving code execution by placing malicious DLL files in the directory of the application.
1Ge
1Cimplicity
Jun 17, 2026
Sep 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control...Show more
GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software. Show less
1Ge
1Cimplicity
Jun 17, 2026
Jul 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issue...Show more
All versions of GE Digital CIMPLICITY that are not adhering to SDG guidance and accepting documents from untrusted sources are vulnerable to memory corruption issues due to insufficient input validation, including issues such as out-of-bounds reads and writes, use-after-free, stack-based buffer overflows, uninitialized pointers, and a heap-based buffer overflow. Successful exploitation could allow an attacker to execute arbitrary code. Show less
1Ge
1Toolboxst
Jun 17, 2026
Apr 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a T...Show more
ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. Show less
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
Kepserver EnterpriseKepware Kepserverex+5 more
Jun 17, 2026
Mar 29, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.Show less
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
Kepserver EnterpriseKepware Kepserverex+5 more
Jun 17, 2026
Mar 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.Show less
1Ge
1Ifix
Jun 17, 2026
Mar 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web serv...Show more
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software. Show less
3Ge
PtcRockwellautomation
9Digital Industrial Gateway Server
Kepserver EnterpriseKepware Server+6 more
Jun 17, 2026
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
3Ge
PtcRockwellautomation
9Digital Industrial Gateway Server
Kepserver EnterpriseKepware Server+6 more
Jun 17, 2026
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.
1Ge
1Proficy Historian
Jun 17, 2026
Jan 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
1Ge
1Proficy Historian
Jun 17, 2026
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An unauthorized user could alter or write files with full control over the path and content of the file.
1Ge
1Proficy Historian
Jun 17, 2026
Jan 18, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An unauthorized user could possibly delete any file on the system.
1Ge
1Proficy Historian
Jun 17, 2026
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
1Ge
1Proficy Historian
Jun 17, 2026
Jan 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
1Ge
1Ms 3000 Firmware
Jun 17, 2026
Jan 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control.
1Ge
1Ms 3000 Firmware
Jun 17, 2026
Jan 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without a...Show more
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.Show less
1Ge
1Ms 3000 Firmware
Jun 17, 2026
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory trave...Show more
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.Show less
1Ge
8Inet 900 Firmware
Inet Ii 900 FirmwareSd1 Firmware+5 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.