Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ge

First CVE: Jan 29, 2008Active for: 18 yearsTotal CVEs: 128
44.7
VTI Score
High

GE's vulnerability footprint spans a portfolio of industrial automation, control systems, and historian software that support critical infrastructure and manufacturing environments, representing a significant attack surface in operational-technology deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the high-value nature of industrial control targets and the accessibility of many GE products to internet-connected networks. The exposure concentrates in flagship products such as CIMPLICITY HMI/SCADA, Proficy Historian, Intelligent Platforms middleware, and the Multilin C70 device firmware, and recurs through weakness classes including hard-coded credentials, buffer-boundary violations, improper input validation, and path-traversal conditions that are endemic to legacy and modern industrial software alike. Defenders should treat GE industrial product advisories as high-priority, inventory affected control systems carefully, and restrict network access to these applications; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
128
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ge over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2008
18 years ago
Most Recent CVE
Nov 30, 2023
967 days ago

Products(227 total)

Top CVEs

Signals from CVEs in this vendor scope (128 CVEs).

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0750HIGH
Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process
Jan 25, 20147.574NOYES
CVE-2012-2516HIGH
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HM
Jul 5, 20129.368NOYES
CVE-2012-2515HIGH
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Docum
Jul 5, 20129.353NOYES
CVE-2016-0861HIGH
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vect
Feb 5, 20168.845NOYES
CVE-2012-6663HIGH
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
Jan 23, 20207.538NOYES
CVE-2016-0862MEDIUM
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information
Feb 5, 20166.537NOYES
CVE-2023-0755CRITICAL
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
Feb 23, 20239.835NONO
CVE-2013-0653MEDIUM
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process
Jan 27, 20134.334NOYES
CVE-2020-27265CRITICAL
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Ent
Jan 14, 20219.833NONO
CVE-2012-3026HIGH
rifsrvd.exe in the Remote Interface Service in GE Intelligent Platforms Proficy Real-Time Information Portal 2.6 through 3.5 SP1 allows remote attackers to cause a denial of servic
Nov 1, 201210.033NONO
View all 128 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products128 CVEs
29%
44%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local26 (20.3%)
Network69 (53.9%)
Unknown29 (22.7%)
Physical3 (2.3%)
Adjacent Network1 (0.8%)
Attack Complexity
Low96 (75.0%)
High3 (2.3%)
Unknown29 (22.7%)
User Interaction
None80 (62.5%)
Unknown29 (22.7%)
Required19 (14.8%)
Privileges Required
Low28 (21.9%)
High3 (2.3%)
None68 (53.1%)
Unknown29 (22.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (128 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
3.9% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ge.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ge — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ge's Products

View all 5 CNAs →

Top CWEs