Resource exhaustion in General Electric Company products - CVE-2022-24118

 

Resource exhaustion in General Electric Company products - CVE-2022-24118

Published: April 4, 2022


Vulnerability identifier: #VU61819
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-24118
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
iNET
iNET II
TD220X
TD220MAX
SD series radio firmware
Software vendor:
General Electric Company

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker on the local network can use the authentication code to cause affected series radios to reset back to the factory default configuration and reboot.


Remediation

Install updates from vendor's website.

External links