9.8

CVE-2022-24119

Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ge ≫ Inet 900 Firmware Version < 8.3.0
   Ge ≫ Inet 900 Version -
Ge ≫ Inet Ii 900 Firmware Version < 8.3.0
   Ge ≫ Inet Ii 900 Version -
Ge ≫ Sd1 Firmware Version <= 6.4.7
   Ge ≫ Sd1 Version -
Ge ≫ Sd2 Firmware Version < 6.4.7
   Ge ≫ Sd2 Version -
Ge ≫ Sd4 Firmware Version < 6.4.7
   Ge ≫ Sd4 Version -
Ge ≫ Sd9 Firmware Version < 6.4.7
   Ge ≫ Sd9 Version -
Ge ≫ Td220max Firmware Version < 1.2.6
   Ge ≫ Td220max Version -
Ge ≫ Td220x Firmware Version < 2.0.16
   Ge ≫ Td220x Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.495
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06
Patch
Third Party Advisory
US Government Resource