9.8

CVE-2022-24116

Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

Data is provided by the National Vulnerability Database (NVD)
GeInet 900 Firmware Version < 8.3.0
   GeInet 900 Version-
GeInet Ii 900 Firmware Version < 8.3.0
   GeInet Ii 900 Version-
GeSd1 Firmware Version <= 6.4.7
   GeSd1 Version-
GeSd2 Firmware Version < 6.4.7
   GeSd2 Version-
GeSd4 Firmware Version < 6.4.7
   GeSd4 Version-
GeSd9 Firmware Version < 6.4.7
   GeSd9 Version-
GeTd220max Firmware Version < 1.2.6
   GeTd220max Version-
GeTd220x Firmware Version < 2.0.16
   GeTd220x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.122
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-325 Missing Cryptographic Step

The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.