← Back

Ge

ge

128 CVEs • 227 products

Products (227)

Click to collapse
Toggle
Cimplicity
cimplicity
Mds Pulsenet
mds_pulsenet
Ifix
ifix
Sd1 Firmware
sd1_firmware
Sd2 Firmware
sd2_firmware
Sd4 Firmware
sd4_firmware
Sd9 Firmware
sd9_firmware
Toolboxst
toolboxst
Workstationst
workstationst
Hydran M2
hydran_m2
Historian
historian
Xeleris
xeleris

CVEs (128)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ge
1Mds Pulsenet
Nov 21, 2024
Jun 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
1Ge
1Mds Pulsenet
Nov 21, 2024
Jun 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code executi...Show more
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.Show less
1Ge
8Pacsystems Cpu320 Firmware
Pacsystems Cru320 FirmwarePacsystems Rsti Ep Cpe 100 Firmware+5 more
Jun 17, 2026
May 18, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, th...Show more
In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.Show less
1Ge
1Centricity Pacs Ra1000
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to by...Show more
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Xeleris
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote a...Show more
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Gemnet License Server
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authenticat...Show more
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1Infinia Hawkeye 4 Firmware
Nov 21, 2024
Mar 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker t...Show more
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authentication and gain access to the affected devices.Show less
1Ge
1D60 Line Distance Relay Firmware
Jun 17, 2026
Feb 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified, which may allow...Show more
A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified, which may allow remote code execution.Show less
1Ge
1D60 Line Distance Relay Firmware
Jun 17, 2026
Feb 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. The SSH functions of the device are vulnerabl...Show more
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior. The SSH functions of the device are vulnerable to buffer overflow conditions that may allow a remote attacker to execute arbitrary code on the device.Show less
1Ge
1Intelligent Platforms Proficy Hmi/scada Cimplicity
May 13, 2026
Oct 5, 2017
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrit...Show more
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution.Show less
1Ge
7Multilink Ml1200 Firmware
Multilink Ml1600 FirmwareMultilink Ml2400 Firmware+4 more
May 13, 2026
Aug 28, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.
1Ge
10Multilin Sr 369 Motor Protection Relay Firmware
Multilin Sr 469 Motor Protection Relay FirmwareMultilin Sr 489 Generator Protection Relay Firmware+7 more
May 13, 2026
Jun 30, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to...Show more
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions. Ciphertext versions of user passwords were created with a non-random initialization vector leaving them susceptible to dictionary attacks. Ciphertext of user passwords can be obtained from the front LCD panel of affected products and through issued Modbus commands.Show less
1Ge
3Cimplicity
HistorianIfix
May 13, 2026
Feb 13, 2017
N/A· v4
6.7 MEDIUM· v3
4.4 MEDIUM· v2
An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior vers...Show more
An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an authenticated session.Show less
1Ge
2Bently Nevada 3500/22m Serial Firmware
Bently Nevada 3500/22m Usb Firmware
May 6, 2026
Nov 25, 2016
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors.
1Ge
1Cimplicity
May 6, 2026
Jul 15, 2016
N/A· v4
6.3 MEDIUM· v3
4.6 MEDIUM· v2
General Electric (GE) Digital Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 27 mishandles service DACLs, which allows local users to modify a service configuration via unspecified vectors.
1Ge
1Multilink Firmware
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote att...Show more
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.Show less
1Ge
1Snmp/web Adapter Firmware
May 6, 2026
Feb 5, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.
1Ge
1Ups Snmp Web Adapter Firmware
May 6, 2026
Feb 5, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
1Ge
1Mds Pulsenet
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files vi...Show more
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.Show less
1Ge
1Mds Pulsenet
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary...Show more
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.Show less