CVE-2022-24116
26.12.2022, 05:15
Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.Enginsight
Vendor | Product | Version |
---|---|---|
ge | inet_900_firmware | 𝑥 < 8.3.0 |
ge | inet_ii_900_firmware | 𝑥 < 8.3.0 |
ge | sd1_firmware | 𝑥 ≤ 6.4.7 |
ge | sd2_firmware | 𝑥 < 6.4.7 |
ge | sd4_firmware | 𝑥 < 6.4.7 |
ge | sd9_firmware | 𝑥 < 6.4.7 |
ge | td220max_firmware | 𝑥 < 1.2.6 |
ge | td220x_firmware | 𝑥 < 2.0.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-326 - Inadequate Encryption StrengthThe software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
- CWE-325 - Missing Cryptographic StepThe product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.