143 results (0.009 seconds)

CVSS: 6.7EPSS: 0%CPEs: 20EXPL: 0

10 Mar 2025 — Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed. Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is... • https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76 • CWE-345: Insufficient Verification of Data Authenticity •

CVSS: 8.3EPSS: 0%CPEs: 1EXPL: 0

10 Mar 2025 — Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network. • https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76 • CWE-306: Missing Authentication for Critical Function •

CVSS: 6.1EPSS: 0%CPEs: 20EXPL: 0

10 Mar 2025 — An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The lack of the IP address and port validation may allow the attacker to bypass firewall rules or to send malicious traffic in the network • https://www.gevernova.com/grid-solutions/app/DownloadFile.aspx?prod=urfamily&type=21&file=76 • CWE-20: Improper Input Validation •

CVSS: 8.4EPSS: 0%CPEs: 3EXPL: 0

14 May 2024 — Elevation of privilege vulnerability in GE HealthCare EchoPAC products Elevación de la vulnerabilidad de privilegios en los productos GE HealthCare EchoPAC • https://securityupdate.gehealthcare.com • CWE-250: Execution with Unnecessary Privileges •

CVSS: 7.6EPSS: 0%CPEs: 3EXPL: 0

14 May 2024 — Insufficiently protected credentials in GE HealthCare EchoPAC products Credenciales insuficientemente protegidas en los productos GE HealthCare EchoPAC • https://securityupdate.gehealthcare.com • CWE-522: Insufficiently Protected Credentials •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

14 May 2024 — Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products Acceso no privilegiado a la vulnerabilidad de archivos críticos en los productos GE HealthCare EchoPAC • https://securityupdate.gehealthcare.com • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 9.6EPSS: 0%CPEs: 3EXPL: 0

14 May 2024 — Weak account password in GE HealthCare EchoPAC products Contraseña de cuenta débil en productos GE HealthCare EchoPAC • https://securityupdate.gehealthcare.com • CWE-798: Use of Hard-coded Credentials •

CVSS: 6.4EPSS: 0%CPEs: 3EXPL: 0

14 May 2024 — Vulnerable data in transit in GE HealthCare EchoPAC products Datos vulnerables en tránsito en productos GE HealthCare EchoPAC • https://securityupdate.gehealthcare.com • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 7.7EPSS: 0%CPEs: 5EXPL: 0

14 May 2024 — Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component Vulnerabilidad de Path Traversal en la función “getAllFolderContents” de Common Service Desktop, un componente del dispositivo de ultrasonido de GE HealthCare • https://securityupdate.gehealthcare.com • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 6.2EPSS: 0%CPEs: 5EXPL: 0

14 May 2024 — Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component Vulnerabilidad de Path Traversal en la función "deleteFiles" de Common Service Desktop, un componente del dispositivo de ultrasonido de GE HealthCare • https://securityupdate.gehealthcare.com • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •