CVE-2022-24117

moderate-risk
Published 2022-12-26

Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

Do I need to act?

-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (8)

Inet 900 Firmware
Inet Ii 900 Firmware
Sd1 Firmware
Sd2 Firmware
Sd4 Firmware
Sd9 Firmware
Td220Max Firmware
Td220X Firmware

Affected Vendors

Ge
46
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 0/34 · Minimal
Exposure 14/34 · Moderate