Baker Hughes's vulnerability footprint concentrates on industrial monitoring and vibration-analysis systems, particularly its Bentley Nevada product line of machinery-condition sensors and firmware, which serve critical infrastructure and manufacturing environments. The recurring exposure pattern centers on authentication and information-disclosure weaknesses—including capture-replay authentication bypasses, cleartext transmission of sensitive data, and missing authentication controls on critical functions—that are characteristic of operational-technology systems designed with availability and simplicity prioritized over modern security isolation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bakerhughes over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29953CRITICAL The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacke | Jul 26, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-29952CRITICAL Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications | Jul 26, 2022 | 9.1 | 27 | NO | NO |
CVE-2023-34441HIGH
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a cleartext transmission vulnerability which could allow an attacker to
steal the authentication | Oct 19, 2023 | 8.2 | 25 | NO | NO |
CVE-2021-32997HIGH The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prio | May 25, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-34437HIGH Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a vulnerability in their password retrieval functionality which could allow an attacker to access pass | Oct 19, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36857MEDIUM
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a replay vulnerability which could allow an attacker to
replay older captured packets of traffi | Oct 19, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bakerhughes.
Media articles that mention a CVE ID that affects a product developed by Bakerhughes — matched by CVE ID, not by vendor name.