Vulnerabilities > GE > Low

DATE CVE VULNERABILITY TITLE RISK
2022-02-25 CVE-2022-23921 Improper Privilege Management vulnerability in GE Proficy Cimplicitiy
Exploitation of this vulnerability may result in local privilege escalation and code execution.
local
high complexity
ge CWE-269
3.7
2021-02-18 CVE-2019-18243 Incorrect Permission Assignment for Critical Resource vulnerability in GE Ifix
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry.
local
low complexity
ge CWE-732
2.1
2021-02-18 CVE-2019-18255 Incorrect Permission Assignment for Critical Resource vulnerability in GE Ifix
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects.
local
low complexity
ge CWE-732
2.1
2019-12-18 CVE-2019-18267 Cross-site Scripting vulnerability in GE S2020 Firmware and S2020G Firmware
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior.
network
ge CWE-79
3.5
2017-08-28 CVE-2015-3976 Cross-site Scripting vulnerability in GE products
Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.
network
ge CWE-79
3.5