First published: Mon Dec 26 2022(Updated: )
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Inet 900 Firmware | <8.3.0 | |
Ge Inet 900 | ||
Ge Inet Ii 900 Firmware | <8.3.0 | |
Ge Inet Ii 900 | ||
Ge Sd1 Firmware | <=6.4.7 | |
Ge Sd1 | ||
Ge Sd2 Firmware | <6.4.7 | |
Ge Sd2 | ||
Ge Sd4 Firmware | <6.4.7 | |
Ge Sd4 | ||
Ge Sd9 Firmware | <6.4.7 | |
Ge Sd9 | ||
Ge Td220max Firmware | <1.2.6 | |
Ge Td220max | ||
Ge Td220x Firmware | <2.0.16 | |
Ge Td220x | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6 are affected.
The severity of CVE-2022-24117 is rated as 9.8 (Critical).
CVE-2022-24117 allows firmware to be downloaded without an integrity check, which can potentially lead to unauthorized access or malicious firmware installation.
To fix CVE-2022-24117, General Electric recommends updating the firmware of affected products to versions that include an integrity check for downloaded firmware.
You can find more information about CVE-2022-24117 on the CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06