← Back

Ge

ge

128 CVEs • 227 products

Products (227)

Click to collapse
Toggle
Cimplicity
cimplicity
Mds Pulsenet
mds_pulsenet
Ifix
ifix
Sd1 Firmware
sd1_firmware
Sd2 Firmware
sd2_firmware
Sd4 Firmware
sd4_firmware
Sd9 Firmware
sd9_firmware
Toolboxst
toolboxst
Workstationst
workstationst
Hydran M2
hydran_m2
Historian
historian
Xeleris
xeleris

CVEs (128)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ge
1Hydran M2
May 6, 2026
Mar 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers t...Show more
The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.Show less
2Ge
Mactek
412400 Level Transmitter Device Type Manager
Bullet Device Type ManagerSvi Ii Ap Positioner Device Type Manager+1 more
May 6, 2026
Feb 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Po...Show more
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 Level Transmitter DTM 1.00.0, allows remote attackers to cause a denial of service (DTM outage) via crafted packets.Show less
1Ge
14Multilink Ml1200
Multilink Ml1200 FirmwareMultilink Ml1600+11 more
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different custo...Show more
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.Show less
1Ge
14Multilink Ml1200
Multilink Ml1200 FirmwareMultilink Ml1600+11 more
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service...Show more
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.Show less
1Ge
1Intelligent Platforms Proficy Hmi/scada Cimplicity
May 6, 2026
Jan 17, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
1Ge
3Intelligent Platforms Proficy Hmi%2fscada Cimplicity
Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer...Show more
The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to execute arbitrary code.Show less
1Ge
3Intelligent Platforms Proficy Hmi%2fscada Cimplicity
Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote a...Show more
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.Show less
2Catapultsoftware
Ge
4Catapult Dnp3 I/o Driver
Intelligent Platforms Proficy Dnp3 I/o DriverIntelligent Platforms Proficy Hmi/scada Cimplicity+1 more
Apr 29, 2026
Nov 22, 2013
N/A· v4
N/A· v3
4.7 MEDIUM· v2
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HM...Show more
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.Show less
2Catapultsoftware
Ge
4Catapult Dnp3 I/o Driver
Intelligent Platforms Proficy Dnp3 I/o DriverIntelligent Platforms Proficy Hmi/scada Cimplicity+1 more
Apr 29, 2026
Nov 22, 2013
N/A· v4
N/A· v3
7.1 HIGH· v2
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HM...Show more
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.Show less
1Ge
2Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems w...Show more
Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP port 10212, aka ZDI-CAN-1621 and ZDI-CAN-1624.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (d...Show more
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote...Show more
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.Show less
1Ge
1Intelligent Platforms Proficy Real Time Information Portal
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote attackers to obtain a username listing via an RMI call.
1Ge
1Intelligent Platforms Proficy Real Time Information Portal
Apr 29, 2026
Jan 27, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to read con...Show more
The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to read configuration files, and discover data-source credentials, via a direct request.Show less
1Ge
3Intelligent Platforms Proficy Hmi/scada Cimplicity
Intelligent Platforms Proficy Process SystemsIntelligent Platforms Proficy Process Systems With Cimplicity
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon...Show more
Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.Show less
1Ge
1Intelligent Platforms Proficy Real Time Information Portal
Apr 29, 2026
Nov 1, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash)...Show more
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3021.Show less
1Ge
1Intelligent Platforms Proficy Real Time Information Portal
Apr 29, 2026
Nov 1, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash)...Show more
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3010 and CVE-2012-3026.Show less
1Ge
1Intelligent Platforms Proficy Real Time Information Portal
Apr 29, 2026
Nov 1, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash)...Show more
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of service (memory corruption and service crash) or possibly execute arbitrary code via long input data, a different vulnerability than CVE-2012-3021 and CVE-2012-3026.Show less
1Ge
5Intelligent Platforms Proficy Batch Execution
Intelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada Ifix+2 more
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse...Show more
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."Show less
2Emc
Ge
7Captiva Quickscan Pro
Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch Execution+4 more
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EM...Show more
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; GE Intelligent Platforms Proficy HMI/SCADA iFIX 5.0 and 5.1; GE Intelligent Platforms Proficy Pulse 1.0; GE Intelligent Platforms Proficy Batch Execution 5.6; GE Intelligent Platforms SI7 I/O Driver 7.20 through 7.42; and other products, allow remote attackers to execute arbitrary code via a long string in the second argument to the (1) JumpMappedID or (2) JumpURL method.Show less