9.8

CVE-2022-24117

Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

Data is provided by the National Vulnerability Database (NVD)
GeInet 900 Firmware Version < 8.3.0
   GeInet 900 Version-
GeInet Ii 900 Firmware Version < 8.3.0
   GeInet Ii 900 Version-
GeSd1 Firmware Version <= 6.4.7
   GeSd1 Version-
GeSd2 Firmware Version < 6.4.7
   GeSd2 Version-
GeSd4 Firmware Version < 6.4.7
   GeSd4 Version-
GeSd9 Firmware Version < 6.4.7
   GeSd9 Version-
GeTd220max Firmware Version < 1.2.6
   GeTd220max Version-
GeTd220x Firmware Version < 2.0.16
   GeTd220x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.247
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-494 Download of Code Without Integrity Check

The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.