GE records
128 published records for vendor ge.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 5 · 3.9%
- Pre-auth RCE
- 25
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-122 Heap-based Buffer Overflow6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
128 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2014-0750Weaponized | GE Proficy HMI/SCADA Path Traversalge · intelligent platforms proficy hmi\%2fscada cimplicity · CWE-22 | High7.5 | — | 70.2% | Jan 25, 2014 |
49Plan | CVE-2012-2516Weaponized | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Histge · intelligent platforms proficy batch execution · CWE-78 | Critical9.3 | — | 39.7% | Jul 4, 2012 |
45Plan | CVE-2012-2515Weaponized | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTemc · captiva quickscan pro · CWE-119 | Critical9.3 | — | 27.6% | Jul 4, 2012 |
43Plan | CVE-2023-0755No exploit | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Critical9.8 | — | 11.8% | Feb 23, 2023 |
43Plan | CVE-2012-0230No exploit | PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers ge · intelligent platforms proficy plant applications · CWE-119 | Critical10.0 | — | 9.2% | Mar 15, 2012 |
42Plan | CVE-2020-27265No exploit | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All verge · industrial gateway server · CWE-121 | Critical9.8 | — | 10.1% | Jan 13, 2021 |
42Plan | CVE-2012-0231No exploit | PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote ge · intelligent platforms proficy plant applications · CWE-119 | Critical10.0 | — | 7.0% | Mar 15, 2012 |
42Plan | CVE-2011-1918No exploit | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 ge · intelligent platforms proficy historian · CWE-119 | Critical10.0 | — | 6.3% | Nov 2, 2011 |
42Plan | CVE-2012-3026No exploit | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Critical10.0 | — | 5.0% | Nov 1, 2012 |
42Plan | CVE-2012-3021No exploit | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Critical10.0 | — | 5.0% | Nov 1, 2012 |
42Plan | CVE-2012-3010No exploit | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Critical10.0 | — | 5.0% | Nov 1, 2012 |
41Plan | CVE-2018-5473No exploit | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runninge · d60 line distance relay firmware · CWE-119 | Critical9.8 | — | 5.9% | Feb 19, 2018 |
41Plan | CVE-2012-0229No exploit | The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of servicege · intelligent platforms proficy historian · CWE-119 | Critical10.0 | — | 5.0% | Mar 15, 2012 |
41Plan | CVE-2011-1919No exploit | Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow ge · intelligent platforms proficy historian · CWE-119 | Critical10.0 | — | 4.6% | Nov 2, 2011 |
41Plan | CVE-2015-6459No exploit | Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Entege · mds pulsenet · CWE-22 | Critical10.0 | — | 3.1% | Sep 18, 2015 |
41Plan | CVE-2016-5788No exploit | General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it ge · bently nevada 3500\/22m usb firmware · CWE-254 | Critical10.0 | — | 2.3% | Nov 24, 2016 |
40Plan | CVE-2018-10611No exploit | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alge · mds pulsenet · CWE-287 | Critical9.8 | — | 5.0% | Jun 4, 2018 |
40Plan | CVE-2017-14002No exploit | GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentige · infinia hawkeye 4 firmware · CWE-287 | Critical9.8 | — | 4.7% | Mar 20, 2018 |
40Plan | CVE-2018-5475No exploit | A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.ge · d60 line distance relay firmware · CWE-121 | Critical9.8 | — | 3.8% | Feb 19, 2018 |
40Plan | CVE-2022-2825No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.ge · industrial gateway server · CWE-121 | Critical9.8 | — | 3.4% | Mar 29, 2023 |
40Plan | CVE-2016-2310No exploit | General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switchesge · multilink firmware · CWE-798 | Critical9.8 | — | 3.2% | Jun 9, 2016 |
40Plan | CVE-2017-14008No exploit | GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.ge · centricity pacs ra1000 · CWE-287 | Critical9.8 | — | 3.0% | Mar 20, 2018 |
40Plan | CVE-2023-0754No exploit | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely ge · digital industrial gateway server · CWE-190 | Critical9.8 | — | 2.9% | Feb 23, 2023 |
40Plan | CVE-2020-12017No exploit | GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.ge · rt430 firmware · CWE-306 | Critical9.8 | — | 2.3% | Jun 2, 2020 |
40Plan | CVE-2008-0174No exploit | GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in basge · proficy real-time information portal · CWE-312 | Critical9.8 | — | 2.0% | Jan 28, 2008 |
- CVE-2014-075051Plan
GE Proficy HMI/SCADA Path Traversal
HighCVSS 7.5WeaponizedEPSS 70%ge · intelligent platforms proficy hmi\%2fscada cimplicityJan 25, 2014
- CVE-2012-251649Plan
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Hist
CriticalCVSS 9.3WeaponizedEPSS 40%ge · intelligent platforms proficy batch executionJul 4, 2012
- CVE-2012-251545Plan
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HT
CriticalCVSS 9.3WeaponizedEPSS 28%emc · captiva quickscan proJul 4, 2012
- CVE-2023-075543Plan
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
CriticalCVSS 9.8No exploitEPSS 12%ge · digital industrial gateway serverFeb 23, 2023
- CVE-2012-023043Plan
PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers
CriticalCVSS 10.0No exploitEPSS 9%ge · intelligent platforms proficy plant applicationsMar 15, 2012
- CVE-2020-2726542Plan
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All ver
CriticalCVSS 9.8No exploitEPSS 10%ge · industrial gateway serverJan 13, 2021
- CVE-2012-023142Plan
PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote
CriticalCVSS 10.0No exploitEPSS 7%ge · intelligent platforms proficy plant applicationsMar 15, 2012
- CVE-2011-191842Plan
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0
CriticalCVSS 10.0No exploitEPSS 6%ge · intelligent platforms proficy historianNov 2, 2011
- CVE-2012-302642Plan
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
CriticalCVSS 10.0No exploitEPSS 5%ge · intelligent platforms proficy real-time information portalNov 1, 2012
- CVE-2012-302142Plan
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
CriticalCVSS 10.0No exploitEPSS 5%ge · intelligent platforms proficy real-time information portalNov 1, 2012
- CVE-2012-301042Plan
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
CriticalCVSS 10.0No exploitEPSS 5%ge · intelligent platforms proficy real-time information portalNov 1, 2012
- CVE-2018-547341Plan
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runnin
CriticalCVSS 9.8No exploitEPSS 6%ge · d60 line distance relay firmwareFeb 19, 2018
- CVE-2012-022941Plan
The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service
CriticalCVSS 10.0No exploitEPSS 5%ge · intelligent platforms proficy historianMar 15, 2012
- CVE-2011-191941Plan
Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow
CriticalCVSS 10.0No exploitEPSS 5%ge · intelligent platforms proficy historianNov 2, 2011
- CVE-2015-645941Plan
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Ente
CriticalCVSS 10.0No exploitEPSS 3%ge · mds pulsenetSep 18, 2015
- CVE-2016-578841Plan
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it
CriticalCVSS 10.0No exploitEPSS 2%ge · bently nevada 3500\/22m usb firmwareNov 24, 2016
- CVE-2018-1061140Plan
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to al
CriticalCVSS 9.8No exploitEPSS 5%ge · mds pulsenetJun 4, 2018
- CVE-2017-1400240Plan
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credenti
CriticalCVSS 9.8No exploitEPSS 5%ge · infinia hawkeye 4 firmwareMar 20, 2018
- CVE-2018-547540Plan
A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.
CriticalCVSS 9.8No exploitEPSS 4%ge · d60 line distance relay firmwareFeb 19, 2018
- CVE-2022-282540Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
CriticalCVSS 9.8No exploitEPSS 3%ge · industrial gateway serverMar 29, 2023
- CVE-2016-231040Plan
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches
CriticalCVSS 9.8No exploitEPSS 3%ge · multilink firmwareJun 9, 2016
- CVE-2017-1400840Plan
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.
CriticalCVSS 9.8No exploitEPSS 3%ge · centricity pacs ra1000Mar 20, 2018
- CVE-2023-075440Plan
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely
CriticalCVSS 9.8No exploitEPSS 3%ge · digital industrial gateway serverFeb 23, 2023
- CVE-2020-1201740Plan
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.
CriticalCVSS 9.8No exploitEPSS 2%ge · rt430 firmwareJun 2, 2020
- CVE-2008-017440Plan
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas
CriticalCVSS 9.8No exploitEPSS 2%ge · proficy real-time information portalJan 28, 2008