Записи GE
128 опубликованных записей вендора ge.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 3,9 %
- Pre-auth RCE
- 25
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer10
- CWE-20 Improper Input Validation9
- CWE-287 Improper Authentication7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-122 Heap-based Buffer Overflow6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
128 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2014-0750Готовый эксплойт | GE Proficy HMI/SCADA Path Traversalge · intelligent platforms proficy hmi\%2fscada cimplicity · CWE-22 | Высокая7,5 | — | 70,2 % | 25 янв. 2014 г. |
49В плане | CVE-2012-2516Готовый эксплойт | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Histge · intelligent platforms proficy batch execution · CWE-78 | Критическая9,3 | — | 39,7 % | 4 июл. 2012 г. |
45В плане | CVE-2012-2515Готовый эксплойт | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTemc · captiva quickscan pro · CWE-119 | Критическая9,3 | — | 27,6 % | 4 июл. 2012 г. |
43В плане | CVE-2023-0755Эксплойта нет | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotege · digital industrial gateway server · CWE-129 | Критическая9,8 | — | 11,8 % | 23 февр. 2023 г. |
43В плане | CVE-2012-0230Эксплойта нет | PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers ge · intelligent platforms proficy plant applications · CWE-119 | Критическая10,0 | — | 9,2 % | 15 мар. 2012 г. |
42В плане | CVE-2020-27265Эксплойта нет | KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All verge · industrial gateway server · CWE-121 | Критическая9,8 | — | 10,1 % | 13 янв. 2021 г. |
42В плане | CVE-2012-0231Эксплойта нет | PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote ge · intelligent platforms proficy plant applications · CWE-119 | Критическая10,0 | — | 7,0 % | 15 мар. 2012 г. |
42В плане | CVE-2011-1918Эксплойта нет | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 ge · intelligent platforms proficy historian · CWE-119 | Критическая10,0 | — | 6,3 % | 2 нояб. 2011 г. |
42В плане | CVE-2012-3026Эксплойта нет | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Критическая10,0 | — | 5,0 % | 1 нояб. 2012 г. |
42В плане | CVE-2012-3021Эксплойта нет | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Критическая10,0 | — | 5,0 % | 1 нояб. 2012 г. |
42В плане | CVE-2012-3010Эксплойта нет | rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remoge · intelligent platforms proficy real-time information portal · CWE-20 | Критическая10,0 | — | 5,0 % | 1 нояб. 2012 г. |
41В плане | CVE-2018-5473Эксплойта нет | An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runninge · d60 line distance relay firmware · CWE-119 | Критическая9,8 | — | 5,9 % | 19 февр. 2018 г. |
41В плане | CVE-2012-0229Эксплойта нет | The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of servicege · intelligent platforms proficy historian · CWE-119 | Критическая10,0 | — | 5,0 % | 15 мар. 2012 г. |
41В плане | CVE-2011-1919Эксплойта нет | Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow ge · intelligent platforms proficy historian · CWE-119 | Критическая10,0 | — | 4,6 % | 2 нояб. 2011 г. |
41В плане | CVE-2015-6459Эксплойта нет | Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Entege · mds pulsenet · CWE-22 | Критическая10,0 | — | 3,1 % | 18 сент. 2015 г. |
41В плане | CVE-2016-5788Эксплойта нет | General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it ge · bently nevada 3500\/22m usb firmware · CWE-254 | Критическая10,0 | — | 2,3 % | 24 нояб. 2016 г. |
40В плане | CVE-2018-10611Эксплойта нет | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to alge · mds pulsenet · CWE-287 | Критическая9,8 | — | 5,0 % | 4 июн. 2018 г. |
40В плане | CVE-2017-14002Эксплойта нет | GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentige · infinia hawkeye 4 firmware · CWE-287 | Критическая9,8 | — | 4,7 % | 20 мар. 2018 г. |
40В плане | CVE-2018-5475Эксплойта нет | A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.ge · d60 line distance relay firmware · CWE-121 | Критическая9,8 | — | 3,8 % | 19 февр. 2018 г. |
40В плане | CVE-2022-2825Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.ge · industrial gateway server · CWE-121 | Критическая9,8 | — | 3,4 % | 29 мар. 2023 г. |
40В плане | CVE-2016-2310Эксплойта нет | General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switchesge · multilink firmware · CWE-798 | Критическая9,8 | — | 3,2 % | 9 июн. 2016 г. |
40В плане | CVE-2017-14008Эксплойта нет | GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.ge · centricity pacs ra1000 · CWE-287 | Критическая9,8 | — | 3,0 % | 20 мар. 2018 г. |
40В плане | CVE-2023-0754Эксплойта нет | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely ge · digital industrial gateway server · CWE-190 | Критическая9,8 | — | 2,9 % | 23 февр. 2023 г. |
40В плане | CVE-2020-12017Эксплойта нет | GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.ge · rt430 firmware · CWE-306 | Критическая9,8 | — | 2,3 % | 2 июн. 2020 г. |
40В плане | CVE-2008-0174Эксплойта нет | GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in basge · proficy real-time information portal · CWE-312 | Критическая9,8 | — | 2,0 % | 28 янв. 2008 г. |
- CVE-2014-075051В плане
GE Proficy HMI/SCADA Path Traversal
ВысокаяCVSS 7,5Готовый эксплойтEPSS 70 %ge · intelligent platforms proficy hmi\%2fscada cimplicity25 янв. 2014 г.
- CVE-2012-251649В плане
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Hist
КритическаяCVSS 9,3Готовый эксплойтEPSS 40 %ge · intelligent platforms proficy batch execution4 июл. 2012 г.
- CVE-2012-251545В плане
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HT
КритическаяCVSS 9,3Готовый эксплойтEPSS 28 %emc · captiva quickscan pro4 июл. 2012 г.
- CVE-2023-075543В плане
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remote
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %ge · digital industrial gateway server23 февр. 2023 г.
- CVE-2012-023043В плане
PRRDS.exe in the Proficy Remote Data Service in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %ge · intelligent platforms proficy plant applications15 мар. 2012 г.
- CVE-2020-2726542В плане
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All ver
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %ge · industrial gateway server13 янв. 2021 г.
- CVE-2012-023142В плане
PRLicenseMgr.exe in the Proficy Server License Manager in GE Intelligent Platforms Proficy Plant Applications 5.0 and earlier allows remote
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %ge · intelligent platforms proficy plant applications15 мар. 2012 г.
- CVE-2011-191842В плане
Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %ge · intelligent platforms proficy historian2 нояб. 2011 г.
- CVE-2012-302642В плане
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ge · intelligent platforms proficy real-time information portal1 нояб. 2012 г.
- CVE-2012-302142В плане
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ge · intelligent platforms proficy real-time information portal1 нояб. 2012 г.
- CVE-2012-301042В плане
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remo
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ge · intelligent platforms proficy real-time information portal1 нояб. 2012 г.
- CVE-2018-547341В плане
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in GE D60 Line Distance Relay devices runnin
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %ge · d60 line distance relay firmware19 февр. 2018 г.
- CVE-2012-022941В плане
The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ge · intelligent platforms proficy historian15 мар. 2012 г.
- CVE-2011-191941В плане
Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %ge · intelligent platforms proficy historian2 нояб. 2011 г.
- CVE-2015-645941В плане
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Ente
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %ge · mds pulsenet18 сент. 2015 г.
- CVE-2016-578841В плане
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %ge · bently nevada 3500\/22m usb firmware24 нояб. 2016 г.
- CVE-2018-1061140В плане
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to al
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ge · mds pulsenet4 июн. 2018 г.
- CVE-2017-1400240В плане
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credenti
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %ge · infinia hawkeye 4 firmware20 мар. 2018 г.
- CVE-2018-547540В плане
A Stack-based Buffer Overflow issue was discovered in GE D60 Line Distance Relay devices running firmware Version 7.11 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ge · d60 line distance relay firmware19 февр. 2018 г.
- CVE-2022-282540В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ge · industrial gateway server29 мар. 2023 г.
- CVE-2016-231040В плане
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ge · multilink firmware9 июн. 2016 г.
- CVE-2017-1400840В плане
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ge · centricity pacs ra100020 мар. 2018 г.
- CVE-2023-075440В плане
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ge · digital industrial gateway server23 февр. 2023 г.
- CVE-2020-1201740В плане
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ge · rt430 firmware2 июн. 2020 г.
- CVE-2008-017440В плане
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in bas
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ge · proficy real-time information portal28 янв. 2008 г.