CVE-2022-24118

CRITICAL WAF: Medium
CVSS 9.1 Published: 2022-12-26
CWE-400 CWE-400

Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection
Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
geinet_900_firmwareup to 8.3.0
geinet_ii_900_firmwareup to 8.3.0
gesd1_firmwareup to 6.4.7
gesd2_firmwareup to 6.4.7
gesd4_firmwareup to 6.4.7
gesd9_firmwareup to 6.4.7
getd220max_firmwareup to 1.2.6
getd220x_firmwareup to 2.0.16

References

  • www.cisa.gov (Patch, Third Party Advisory, US Government Resource)
Back to CVE Database