CVE-2022-24117
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.3.0 |
| Running on/with | Platform Versions |
|---|---|
Ge Inet 900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.3.0 |
| Running on/with | Platform Versions |
|---|---|
Ge Inet Ii 900 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd4 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.4.7 |
| Running on/with | Platform Versions |
|---|---|
Ge Sd9 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.6 |
| Running on/with | Platform Versions |
|---|---|
Ge Td220max | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.16 |
| Running on/with | Platform Versions |
|---|---|
Ge Td220x | All versions |
References (2)
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.