First published: Mon Dec 26 2022(Updated: )
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
General Electric Renewable Energy iNET/iNET II series radio firmware | ||
General Electric Renewable Energy SD series radio firmware | ||
General Electric Renewable Energy TD220X series radio firmware | ||
General Electric Renewable Energy TD220MAX series radio firmware | ||
GE Inet 900 | <8.3.0 | |
GE Inet 900 Firmware | ||
General Electric Renewable Energy iNET/iNET II series radio firmware | <8.3.0 | |
GE INET II 900 Firmware | ||
GE SD1 | <=6.4.7 | |
Hametech Hame SD1 Wi-Fi | ||
GE SD2 | <6.4.7 | |
GE SD2 | ||
GE SD4 | <6.4.7 | |
GE SD4 Firmware | ||
GE SD9 | <6.4.7 | |
GE SD9 Firmware | ||
General Electric Renewable Energy TD220MAX series radio firmware | <1.2.6 | |
Ge Td220max Firmware | ||
General Electric Renewable Energy TD220X series radio firmware | <2.0.16 | |
GE TD220X Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6 are affected.
The severity of CVE-2022-24117 is rated as 9.8 (Critical).
CVE-2022-24117 allows firmware to be downloaded without an integrity check, which can potentially lead to unauthorized access or malicious firmware installation.
To fix CVE-2022-24117, General Electric recommends updating the firmware of affected products to versions that include an integrity check for downloaded firmware.
You can find more information about CVE-2022-24117 on the CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06