← Back

Ge

ge

128 CVEs • 227 products

Products (227)

Click to collapse
Toggle
Cimplicity
cimplicity
Mds Pulsenet
mds_pulsenet
Ifix
ifix
Sd1 Firmware
sd1_firmware
Sd2 Firmware
sd2_firmware
Sd4 Firmware
sd4_firmware
Sd9 Firmware
sd9_firmware
Toolboxst
toolboxst
Workstationst
workstationst
Hydran M2
hydran_m2
Historian
historian
Xeleris
xeleris

CVEs (128)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ge
8Inet 900 Firmware
Inet Ii 900 FirmwareSd1 Firmware+5 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
1Ge
8Inet 900 Firmware
Inet Ii 900 FirmwareSd1 Firmware+5 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0....Show more
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.Show less
1Ge
8Inet 900 Firmware
Inet Ii 900 FirmwareSd1 Firmware+5 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
1Ge
8Inet 900 Firmware
Inet Ii 900 FirmwareSd1 Firmware+5 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
1Ge
1Cimplicity
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code.
1Ge
1Cimplicity
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code.
1Ge
1Cimplicity
Jun 17, 2026
Dec 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
1Ge
1Cimplicity
Jun 17, 2026
Dec 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code.
1Ge
1Cimplicity
Jun 17, 2026
Dec 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
1Ge
1Workstationst
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker to compromise a victim's browser/session. WorkstationST is only deploy...Show more
An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15) and could allow an attacker to compromise a victim's browser/session. WorkstationST is only deployed in specific, controlled environments rendering attack complexity significantly higher than if the attack were conducted on the software in isolation. WorkstationST v07.09.15 can be found in ControlST v07.09.07 SP8 and greater.Show less
1Ge
1Workstationst
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specifi...Show more
A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specific, controlled environments rendering attack complexity significantly higher than if the attack were conducted on the software in isolation. WorkstationST v07.09.15 can be found in ControlST v07.09.07 SP8 and greater.Show less
1Ge
1Voluson S8 Firmware
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might introduce an excessive attack surface. Access to the local network is requi...Show more
A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might introduce an excessive attack surface. Access to the local network is required for this attack to succeed.Show less
1Ge
1Voluson S8 Firmware
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibili...Show more
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.Show less
1Ge
1Voluson S8 Firmware
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change th...Show more
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credentials. Attacking locally is a requirement. It is recommended to change the configuration settings.Show less
1Ge
1Toolboxst
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected...Show more
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.Show less
1Ge
1Ur Bootloader Binary
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.
1Ge
19Multilin B30 Firmware
Multilin B90 FirmwareMultilin C30 Firmware+16 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before up...Show more
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.Show less
1Ge
19Multilin B30 Firmware
Multilin B90 FirmwareMultilin C30 Firmware+16 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.
1Ge
19Multilin B30 Firmware
Multilin B90 FirmwareMultilin C30 Firmware+16 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a “Last-key pressed” MODBUS register can be used to gain unauthorized information.
1Ge
19Multilin B30 Firmware
Multilin B90 FirmwareMultilin C30 Firmware+16 more
Jun 17, 2026
Mar 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.