SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24120

Certain General Electric Renewable Energy products store cleartext credentials in flash memory.

MEDIUM 4.6EPSS 0.18%

Does this matter?

Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.

Description

Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.

CVSS 3.1
4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.18% probability · 8th percentile
CISA KEV
Not listed
Weakness
CWE-312
Affected
ge/inet 900 firmware · ge/inet ii 900 firmware · ge/sd1 firmware · ge/sd2 firmware · ge/sd4 firmware · ge/sd9 firmware · ge/td220max firmware · ge/td220x firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.