logo

DHS: Hard-Coded Password Found in GE Industrial Networking Gear

ID: 8736fc6b-f050-58ab-9cb9-bd55d24b2ead

STIX ID: report--8736fc6b-f050-58ab-9cb9-bd55d24b2ead

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2016-06-03

Date Updated: 2026-05-05

Author: Paul Roberts

...
...

ICS-CERT and DHS warn that many GE MultiLink industrial Ethernet switches contain a hard-coded administrative account (CVE-2016-2310b) that could allow remote unauthorized administrative access. GE released firmware updates to remove the default account for specific MultiLink models; organizations are advised to evaluate impact and apply the updates. The advisory notes no confirmed exploitation but emphasizes the high relevance for critical infrastructure deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.