9.1

CVE-2022-24118

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

Data is provided by the National Vulnerability Database (NVD)
GeInet 900 Firmware Version < 8.3.0
   GeInet 900 Version-
GeInet Ii 900 Firmware Version < 8.3.0
   GeInet Ii 900 Version-
GeSd1 Firmware Version <= 6.4.7
   GeSd1 Version-
GeSd2 Firmware Version < 6.4.7
   GeSd2 Version-
GeSd4 Firmware Version < 6.4.7
   GeSd4 Version-
GeSd9 Firmware Version < 6.4.7
   GeSd9 Version-
GeTd220max Firmware Version < 1.2.6
   GeTd220max Version-
GeTd220x Firmware Version < 2.0.16
   GeTd220x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.177
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.