Ge
ge
128 CVEs • 227 products
Products (227)
Click to collapseToggle
Products (227)
Click to collapse
CVEs (128)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ge 1Asset Performance Management Classic Jun 17, 2026 Sep 23, 2020 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform a...Show more |
1Ge 1Asset Performance Management Classic Jun 17, 2026 Sep 23, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users who should not have...Show more |
1Ge 3Rt430 Firmware Rt431 FirmwareRt434 FirmwareJun 17, 2026 Jun 2, 2020 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious i...Show more |
A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to th...Show more |
GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instr...Show more |
GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. GE recommends that users disable the Telnet service. |
1Ge 16Invenia Abus Scan Station Firmware Logiq E10 FirmwareLogiq E9 Firmware+13 moreJun 17, 2026 Feb 20, 2020 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to t...Show more |
1Ge 2D200 Firmware D20me FirmwareNov 21, 2024 Jan 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 General Electric D20ME devices are not properly configured and reveal plaintext passwords. |
1Ge 2S2020 Firmware S2020g FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back...Show more |
1Ge 4Aespire 7100 Firmware Aespire 7900 FirmwareAestiva 7100 Firmware+1 moreJun 17, 2026 Jul 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remot...Show more |
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system. |
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system dur...Show more |
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall...Show more |
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements. |
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scrip...Show more |
1Ge 3Ex2100e Firmware Ls2100e FirmwareMark Vle FirmwareNov 21, 2024 Dec 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GE Mark VIe, EX2100e, EX2100e_Reg, and LS2100e Versions 03.03.28C to 05.02.04C, EX2100e All versions prior to v04.09.00C, EX2100e_Reg All versions prior to v04.09.00C, and LS2100e All versions prior to v04.09.00C The aff...Show more |
XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0 |
Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the third-party ActiveX object provided to GE iFIX versions 2.0 - 5.8 by Gigasoft. Only the independent...Show more |
2Ge Gigasoft2Ge Communicator ProessentialsNov 21, 2024 Oct 2, 2018 N/A· v4 7.6 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via u...Show more |
Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform. |