GE kayıtları
ge üreticisine ait 128 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %3,9
- Pre-auth RCE
- 25
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-122 Heap-based Buffer Overflow6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
128 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2014-0750Silahlaştırılmış | GE Proficy HMI/SCADA Path Traversalge · intelligent platforms proficy hmi\%2fscada cimplicity · CWE-22 | Yüksek7,5 | — | %70,2 | 25 Oca 2014 |
49Planlayın | CVE-2012-2516Silahlaştırılmış | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Histge · intelligent platforms proficy batch execution · CWE-78 | Kritik9,3 | — | %39,7 | 4 Tem 2012 |
45Planlayın | CVE-2012-2515Silahlaştırılmış | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTemc · captiva quickscan pro · CWE-119 | Kritik9,3 | — | %27,6 | 4 Tem 2012 |
43Planlayın | CVE-2023-0755İstismar yok | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Kritik9,8 | — | %11,8 | 23 Şub 2023 |
43Planlayın | CVE-2012-0230İstismar yok | PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers ge · intelligent platforms proficy plant applications · CWE-119 | Kritik10,0 | — | %9,2 | 15 Mar 2012 |
42Planlayın | CVE-2020-27265İstismar yok | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All verge · industrial gateway server · CWE-121 | Kritik9,8 | — | %10,1 | 13 Oca 2021 |
42Planlayın | CVE-2012-0231İstismar yok | PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote ge · intelligent platforms proficy plant applications · CWE-119 | Kritik10,0 | — | %7,0 | 15 Mar 2012 |
42Planlayın | CVE-2011-1918İstismar yok | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 ge · intelligent platforms proficy historian · CWE-119 | Kritik10,0 | — | %6,3 | 2 Kas 2011 |
42Planlayın | CVE-2012-3026İstismar yok | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Kritik10,0 | — | %5,0 | 1 Kas 2012 |
42Planlayın | CVE-2012-3021İstismar yok | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Kritik10,0 | — | %5,0 | 1 Kas 2012 |
42Planlayın | CVE-2012-3010İstismar yok | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Kritik10,0 | — | %5,0 | 1 Kas 2012 |
41Planlayın | CVE-2018-5473İstismar yok | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runninge · d60 line distance relay firmware · CWE-119 | Kritik9,8 | — | %5,9 | 19 Şub 2018 |
41Planlayın | CVE-2012-0229İstismar yok | The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of servicege · intelligent platforms proficy historian · CWE-119 | Kritik10,0 | — | %5,0 | 15 Mar 2012 |
41Planlayın | CVE-2011-1919İstismar yok | Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow ge · intelligent platforms proficy historian · CWE-119 | Kritik10,0 | — | %4,6 | 2 Kas 2011 |
41Planlayın | CVE-2015-6459İstismar yok | Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Entege · mds pulsenet · CWE-22 | Kritik10,0 | — | %3,1 | 18 Eyl 2015 |
41Planlayın | CVE-2016-5788İstismar yok | General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it ge · bently nevada 3500\/22m usb firmware · CWE-254 | Kritik10,0 | — | %2,3 | 24 Kas 2016 |
40Planlayın | CVE-2018-10611İstismar yok | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alge · mds pulsenet · CWE-287 | Kritik9,8 | — | %5,0 | 4 Haz 2018 |
40Planlayın | CVE-2017-14002İstismar yok | GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentige · infinia hawkeye 4 firmware · CWE-287 | Kritik9,8 | — | %4,7 | 20 Mar 2018 |
40Planlayın | CVE-2018-5475İstismar yok | A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.ge · d60 line distance relay firmware · CWE-121 | Kritik9,8 | — | %3,8 | 19 Şub 2018 |
40Planlayın | CVE-2022-2825İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.ge · industrial gateway server · CWE-121 | Kritik9,8 | — | %3,4 | 29 Mar 2023 |
40Planlayın | CVE-2016-2310İstismar yok | General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switchesge · multilink firmware · CWE-798 | Kritik9,8 | — | %3,2 | 9 Haz 2016 |
40Planlayın | CVE-2017-14008İstismar yok | GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.ge · centricity pacs ra1000 · CWE-287 | Kritik9,8 | — | %3,0 | 20 Mar 2018 |
40Planlayın | CVE-2023-0754İstismar yok | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely ge · digital industrial gateway server · CWE-190 | Kritik9,8 | — | %2,9 | 23 Şub 2023 |
40Planlayın | CVE-2020-12017İstismar yok | GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.ge · rt430 firmware · CWE-306 | Kritik9,8 | — | %2,3 | 2 Haz 2020 |
40Planlayın | CVE-2008-0174İstismar yok | GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in basge · proficy real-time information portal · CWE-312 | Kritik9,8 | — | %2,0 | 28 Oca 2008 |
- CVE-2014-075051Planlayın
GE Proficy HMI/SCADA Path Traversal
YüksekCVSS 7,5SilahlaştırılmışEPSS %70ge · intelligent platforms proficy hmi\%2fscada cimplicity25 Oca 2014
- CVE-2012-251649Planlayın
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Hist
KritikCVSS 9,3SilahlaştırılmışEPSS %40ge · intelligent platforms proficy batch execution4 Tem 2012
- CVE-2012-251545Planlayın
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HT
KritikCVSS 9,3SilahlaştırılmışEPSS %28emc · captiva quickscan pro4 Tem 2012
- CVE-2023-075543Planlayın
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
KritikCVSS 9,8İstismar yokEPSS %12ge · digital industrial gateway server23 Şub 2023
- CVE-2012-023043Planlayın
PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers
KritikCVSS 10,0İstismar yokEPSS %9ge · intelligent platforms proficy plant applications15 Mar 2012
- CVE-2020-2726542Planlayın
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All ver
KritikCVSS 9,8İstismar yokEPSS %10ge · industrial gateway server13 Oca 2021
- CVE-2012-023142Planlayın
PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote
KritikCVSS 10,0İstismar yokEPSS %7ge · intelligent platforms proficy plant applications15 Mar 2012
- CVE-2011-191842Planlayın
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0
KritikCVSS 10,0İstismar yokEPSS %6ge · intelligent platforms proficy historian2 Kas 2011
- CVE-2012-302642Planlayın
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
KritikCVSS 10,0İstismar yokEPSS %5ge · intelligent platforms proficy real-time information portal1 Kas 2012
- CVE-2012-302142Planlayın
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
KritikCVSS 10,0İstismar yokEPSS %5ge · intelligent platforms proficy real-time information portal1 Kas 2012
- CVE-2012-301042Planlayın
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
KritikCVSS 10,0İstismar yokEPSS %5ge · intelligent platforms proficy real-time information portal1 Kas 2012
- CVE-2018-547341Planlayın
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runnin
KritikCVSS 9,8İstismar yokEPSS %6ge · d60 line distance relay firmware19 Şub 2018
- CVE-2012-022941Planlayın
The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service
KritikCVSS 10,0İstismar yokEPSS %5ge · intelligent platforms proficy historian15 Mar 2012
- CVE-2011-191941Planlayın
Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow
KritikCVSS 10,0İstismar yokEPSS %5ge · intelligent platforms proficy historian2 Kas 2011
- CVE-2015-645941Planlayın
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Ente
KritikCVSS 10,0İstismar yokEPSS %3ge · mds pulsenet18 Eyl 2015
- CVE-2016-578841Planlayın
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it
KritikCVSS 10,0İstismar yokEPSS %2ge · bently nevada 3500\/22m usb firmware24 Kas 2016
- CVE-2018-1061140Planlayın
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to al
KritikCVSS 9,8İstismar yokEPSS %5ge · mds pulsenet4 Haz 2018
- CVE-2017-1400240Planlayın
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credenti
KritikCVSS 9,8İstismar yokEPSS %5ge · infinia hawkeye 4 firmware20 Mar 2018
- CVE-2018-547540Planlayın
A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.
KritikCVSS 9,8İstismar yokEPSS %4ge · d60 line distance relay firmware19 Şub 2018
- CVE-2022-282540Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
KritikCVSS 9,8İstismar yokEPSS %3ge · industrial gateway server29 Mar 2023
- CVE-2016-231040Planlayın
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches
KritikCVSS 9,8İstismar yokEPSS %3ge · multilink firmware9 Haz 2016
- CVE-2017-1400840Planlayın
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.
KritikCVSS 9,8İstismar yokEPSS %3ge · centricity pacs ra100020 Mar 2018
- CVE-2023-075440Planlayın
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely
KritikCVSS 9,8İstismar yokEPSS %3ge · digital industrial gateway server23 Şub 2023
- CVE-2020-1201740Planlayın
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.
KritikCVSS 9,8İstismar yokEPSS %2ge · rt430 firmware2 Haz 2020
- CVE-2008-017440Planlayın
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas
KritikCVSS 9,8İstismar yokEPSS %2ge · proficy real-time information portal28 Oca 2008