CVE-2022-24117
26.12.2022, 05:15
Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ge | inet_900_firmware | 𝑥 < 8.3.0 |
| ge | inet_ii_900_firmware | 𝑥 < 8.3.0 |
| ge | sd1_firmware | 𝑥 ≤ 6.4.7 |
| ge | sd2_firmware | 𝑥 < 6.4.7 |
| ge | sd4_firmware | 𝑥 < 6.4.7 |
| ge | sd9_firmware | 𝑥 < 6.4.7 |
| ge | td220max_firmware | 𝑥 < 1.2.6 |
| ge | td220x_firmware | 𝑥 < 2.0.16 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration