Vulnerabilities > GE

DATE CVE VULNERABILITY TITLE RISK
2021-03-25 CVE-2021-27448 Improper Privilege Management vulnerability in GE Mu320E Firmware
A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E (all firmware versions prior to v04A00.1).
local
low complexity
ge CWE-269
7.8
2021-03-25 CVE-2021-27440 Use of Hard-coded Credentials vulnerability in GE Reason Dr60 Firmware
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
network
low complexity
ge CWE-798
critical
9.8
2021-03-25 CVE-2021-27438 Use of Hard-coded Credentials vulnerability in GE Reason Dr60 Firmware
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
network
low complexity
ge CWE-798
8.8
2021-02-18 CVE-2019-18243 Incorrect Permission Assignment for Critical Resource vulnerability in GE Ifix
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry.
local
low complexity
ge CWE-732
5.5
2021-02-18 CVE-2019-18255 Incorrect Permission Assignment for Critical Resource vulnerability in GE Ifix
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects.
local
low complexity
ge CWE-732
5.5
2021-01-14 CVE-2020-27267 Out-of-bounds Write vulnerability in multiple products
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.1
2021-01-14 CVE-2020-27265 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.8
2021-01-14 CVE-2020-27263 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.1
2020-10-20 CVE-2020-16246 Unspecified vulnerability in GE S2020 Firmware and S2024 Firmware
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the victim client.
network
low complexity
ge
6.1
2020-09-25 CVE-2020-16242 Unspecified vulnerability in GE S2020 Firmware and S2024 Firmware
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.
network
low complexity
ge
6.1