Vulnerabilities > GE

DATE CVE VULNERABILITY TITLE RISK
2016-02-05 CVE-2016-0861 Command Injection vulnerability in GE UPS Snmp web Adapter Firmware
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
network
low complexity
ge CWE-77
critical
9.0
2015-09-18 CVE-2015-6459 Path Traversal vulnerability in GE MDS Pulsenet
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.
network
low complexity
ge CWE-22
critical
10.0
2015-09-18 CVE-2015-6456 Unspecified vulnerability in GE MDS Pulsenet
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.
network
low complexity
ge
critical
9.0
2015-03-14 CVE-2014-5409 Predictable Random Number Generator Weakness in General Electric (GE) Hydran M2
The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.
network
low complexity
ge
5.0
2015-02-07 CVE-2014-9203 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 Level Transmitter DTM 1.00.0, allows remote attackers to cause a denial of service (DTM outage) via crafted packets.
network
low complexity
ge mactek CWE-119
5.0
2015-01-17 CVE-2014-5419 Cryptographic Issues vulnerability in GE products
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.
network
low complexity
ge CWE-310
5.0
2015-01-17 CVE-2014-5418 Resource Management Errors vulnerability in GE products
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.
network
low complexity
ge CWE-399
7.8
2015-01-17 CVE-2014-2355 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GE Intelligent Platforms Proficy Hmi/Scada Cimplicity
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.
local
ge CWE-119
6.9
2014-01-25 CVE-2014-0751 Path Traversal vulnerability in GE products
Directory traversal vulnerability in CimWebServer.exe (aka the WebView component) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted message to TCP port 10212, aka ZDI-CAN-1623.
network
low complexity
ge CWE-22
7.5
2014-01-25 CVE-2014-0750 Path Traversal vulnerability in GE products
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.
network
low complexity
ge CWE-22
7.5