Lucene search

K
cveMitreCVE-2022-24116
HistoryDec 26, 2022 - 5:15 a.m.

CVE-2022-24116

2022-12-2605:15:10
CWE-326
mitre
web.nvd.nist.gov
35
general electric
renewable energy
inadequate encryption
inet
inet ii
cve-2022-24116
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

48.6%

Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

Affected configurations

Nvd
Node
geinet_900_firmwareRange<8.3.0
AND
geinet_900Match-
Node
geinet_ii_900_firmwareRange<8.3.0
AND
geinet_ii_900Match-
Node
gesd1_firmwareRange6.4.7
AND
gesd1Match-
Node
gesd2_firmwareRange<6.4.7
AND
gesd2Match-
Node
gesd4_firmwareRange<6.4.7
AND
gesd4Match-
Node
gesd9_firmwareRange<6.4.7
AND
gesd9Match-
Node
getd220max_firmwareRange<1.2.6
AND
getd220maxMatch-
Node
getd220x_firmwareRange<2.0.16
AND
getd220xMatch-
VendorProductVersionCPE
geinet_900_firmware*cpe:2.3:o:ge:inet_900_firmware:*:*:*:*:*:*:*:*
geinet_900-cpe:2.3:h:ge:inet_900:-:*:*:*:*:*:*:*
geinet_ii_900_firmware*cpe:2.3:o:ge:inet_ii_900_firmware:*:*:*:*:*:*:*:*
geinet_ii_900-cpe:2.3:h:ge:inet_ii_900:-:*:*:*:*:*:*:*
gesd1_firmware*cpe:2.3:o:ge:sd1_firmware:*:*:*:*:*:*:*:*
gesd1-cpe:2.3:h:ge:sd1:-:*:*:*:*:*:*:*
gesd2_firmware*cpe:2.3:o:ge:sd2_firmware:*:*:*:*:*:*:*:*
gesd2-cpe:2.3:h:ge:sd2:-:*:*:*:*:*:*:*
gesd4_firmware*cpe:2.3:o:ge:sd4_firmware:*:*:*:*:*:*:*:*
gesd4-cpe:2.3:h:ge:sd4:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

48.6%

Related for CVE-2022-24116