CVE-2022-24117: Critical severity general electric renewable energy inet/inet ii series radio firmware vulnerability
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What General Electric Renewable Energy products are affected by CVE-2022-24117?
iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6 are affected.
What is the severity of CVE-2022-24117?
The severity of CVE-2022-24117 is rated as 9.8 (Critical).
How does CVE-2022-24117 affect General Electric Renewable Energy products?
CVE-2022-24117 allows firmware to be downloaded without an integrity check, which can potentially lead to unauthorized access or malicious firmware installation.
How can I fix CVE-2022-24117?
To fix CVE-2022-24117, General Electric recommends updating the firmware of affected products to versions that include an integrity check for downloaded firmware.
Where can I find more information about CVE-2022-24117?
You can find more information about CVE-2022-24117 on the CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06