CVE-2022-24119: Critical severity general electric renewable energy inet/inet ii series radio firmware vulnerability
Published Dec 26, 2022
·Updated
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
Affected Software
20 affected components
General Electric Renewable Energy iNET/iNET II series radio firmware versions prior to rev. 8.3.0
General Electric Renewable Energy SD series radio firmware versions prior to rev. 6.4.7
General Electric Renewable Energy TD220X series radio firmware versions prior to rev. 2.0.16
General Electric Renewable Energy TD220MAX series radio firmware versions prior to rev. 1.2.6
GE Inet 900 Firmware<8.3.0
GE Inet 900
GE Inet Ii 900 Firmware<8.3.0
GE Inet Ii 900
GE Sd1 Firmware<=6.4.7
GE Sd1
GE Sd2 Firmware<6.4.7
GE Sd2
GE Sd4 Firmware<6.4.7
GE Sd4
GE Sd9 Firmware<6.4.7
GE Sd9
GE Td220max Firmware<1.2.6
GE TD220MAX
GE Td220x Firmware<2.0.16
GE TD220X
Remediation
Patch Available
Event History
Dec 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Aug 3, 2024
Data Sourced
via ICS·04:09 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-24119.
2
What is the severity of CVE-2022-24119?
The severity of CVE-2022-24119 is critical with a severity value of 9.8.
3
Which General Electric Renewable Energy products are affected by CVE-2022-24119?
The General Electric Renewable Energy products affected by CVE-2022-24119 are iNET and iNET II before version 8.3.0.
4
How can I fix the CVE-2022-24119 vulnerability?
To fix the CVE-2022-24119 vulnerability, update your General Electric Renewable Energy products to version 8.3.0 or later.
5
Where can I find more information about CVE-2022-24119?
You can find more information about CVE-2022-24119 on the official CISA website: https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06