CVE-2022-24118: Critical severity general electric renewable energy inet/inet ii series radio firmware vulnerability
Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-24118?
CVE-2022-24118 is a vulnerability that allows attackers to use a code to trigger a reboot into the factory default configuration in certain General Electric Renewable Energy products.
Which General Electric Renewable Energy products are affected by CVE-2022-24118?
CVE-2022-24118 affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.
What is the severity of CVE-2022-24118?
CVE-2022-24118 has a severity rating of 9.1 (critical).
How can attackers exploit CVE-2022-24118?
Attackers can exploit CVE-2022-24118 by using a code to trigger a reboot into the factory default configuration.
Is there a fix for CVE-2022-24118?
To fix CVE-2022-24118, update the affected General Electric Renewable Energy products to versions higher than the vulnerable ones mentioned.