VYPR

iNET II

by General Electric (GE)

CVEs (5)

  • CVE-2022-24119CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.

  • CVE-2022-24117CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

  • CVE-2022-24116CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.00

    Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0.

  • CVE-2022-24118CriDec 26, 2022
    risk 0.59cvss 9.1epss 0.01

    Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6.

  • CVE-2022-24120MedDec 26, 2022
    risk 0.30cvss 4.6epss 0.00

    Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0.