9.8

CVE-2022-24116

Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeInet 900 Firmware Version < 8.3.0
   GeInet 900 Version-
GeInet Ii 900 Firmware Version < 8.3.0
   GeInet Ii 900 Version-
GeSd1 Firmware Version <= 6.4.7
   GeSd1 Version-
GeSd2 Firmware Version < 6.4.7
   GeSd2 Version-
GeSd4 Firmware Version < 6.4.7
   GeSd4 Version-
GeSd9 Firmware Version < 6.4.7
   GeSd9 Version-
GeTd220max Firmware Version < 1.2.6
   GeTd220max Version-
GeTd220x Firmware Version < 2.0.16
   GeTd220x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.122
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.