MEDIUM · 4.6

CVE-2022-24120

Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

Vulnerability Description

Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

CVSS Score

4.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GeInet 900 Firmware< 8.3.0
GeInet 900-
GeInet Ii 900 Firmware< 8.3.0
GeInet Ii 900-
GeSd1 Firmware<= 6.4.7
GeSd1-
GeSd2 Firmware< 6.4.7
GeSd2-
GeSd4 Firmware< 6.4.7
GeSd4-
GeSd9 Firmware< 6.4.7
GeSd9-
GeTd220Max Firmware< 1.2.6
GeTd220Max-
GeTd220X Firmware< 2.0.16
GeTd220X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-24120?

CVE-2022-24120 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

How severe is CVE-2022-24120?

CVE-2022-24120 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-24120?

Check the references section above for vendor advisories and patch information. Affected products include: Ge Inet 900 Firmware, Ge Inet 900, Ge Inet Ii 900 Firmware, Ge Inet Ii 900, Ge Sd1 Firmware.