4.6

CVE-2022-24120

Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

Data is provided by the National Vulnerability Database (NVD)
GeInet 900 Firmware Version < 8.3.0
   GeInet 900 Version-
GeInet Ii 900 Firmware Version < 8.3.0
   GeInet Ii 900 Version-
GeSd1 Firmware Version <= 6.4.7
   GeSd1 Version-
GeSd2 Firmware Version < 6.4.7
   GeSd2 Version-
GeSd4 Firmware Version < 6.4.7
   GeSd4 Version-
GeSd9 Firmware Version < 6.4.7
   GeSd9 Version-
GeTd220max Firmware Version < 1.2.6
   GeTd220max Version-
GeTd220x Firmware Version < 2.0.16
   GeTd220x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.044
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.