On a recent pentest, I found few vulnerabilities in GE Industrial Solutions - UPS SNMP Adapter. Successful exploitation can lead to arbitrary command execution as superuser on the device, and sensitive information leakage.
GE Advisory: http://apps.geindustrial.com/publibrary/checkout/GEIS_SNMP?TNR=Application%20and%20Technical|GEIS_SNMP|PDF&filename=GEIS_SNMP.pdf
• All SNMP/Web Interface cards with firmware version prior to 4.8 manufactured by GE Industrial Solutions.
Read on for details and poc.