CVE-2022-24116
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.3.0 |
| Running on/with | Platform Versions |
|---|---|
Ge Inet 900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.3.0 |
| Running on/with | Platform Versions |
|---|---|
Ge Inet Ii 900 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd4 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd9 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.6 |
| Running on/with | Platform Versions |
|---|---|
Ge Td220max | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.16 |
| Running on/with | Platform Versions |
|---|---|
Ge Td220x | All versions |
Related CWEs
CWE-325
Missing Cryptographic Step
The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.