GE's vulnerability footprint spans a portfolio of industrial automation, control systems, and historian software that support critical infrastructure and manufacturing environments, representing a significant attack surface in operational-technology deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the high-value nature of industrial control targets and the accessibility of many GE products to internet-connected networks. The exposure concentrates in flagship products such as CIMPLICITY HMI/SCADA, Proficy Historian, Intelligent Platforms middleware, and the Multilin C70 device firmware, and recurs through weakness classes including hard-coded credentials, buffer-boundary violations, improper input validation, and path-traversal conditions that are endemic to legacy and modern industrial software alike. Defenders should treat GE industrial product advisories as high-priority, inventory affected control systems carefully, and restrict network access to these applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ge over time
Signals from CVEs in this vendor scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0750HIGH Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process | Jan 25, 2014 | 7.5 | 74 | NO | YES |
CVE-2012-2516HIGH An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HM | Jul 5, 2012 | 9.3 | 68 | NO | YES |
CVE-2012-2515HIGH Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Docum | Jul 5, 2012 | 9.3 | 53 | NO | YES |
CVE-2016-0861HIGH General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vect | Feb 5, 2016 | 8.8 | 45 | NO | YES |
CVE-2012-6663HIGH General Electric D20ME devices are not properly configured and reveal plaintext passwords. | Jan 23, 2020 | 7.5 | 38 | NO | YES |
CVE-2016-0862MEDIUM General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information | Feb 5, 2016 | 6.5 | 37 | NO | YES |
CVE-2023-0755CRITICAL
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
| Feb 23, 2023 | 9.8 | 35 | NO | NO |
CVE-2013-0653MEDIUM Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process | Jan 27, 2013 | 4.3 | 34 | NO | YES |
CVE-2020-27265CRITICAL KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Ent | Jan 14, 2021 | 9.8 | 33 | NO | NO |
CVE-2012-3026HIGH rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of servic | Nov 1, 2012 | 10.0 | 33 | NO | NO |
Signals from CVEs in this vendor scope (128 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ge.
Media articles that mention a CVE ID that affects a product developed by Ge — matched by CVE ID, not by vendor name.