Resource exhaustion in General Electric Company products - CVE-2022-24118
Published: April 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker on the local network can use the authentication code to cause affected series radios to reset back to the factory default configuration and reboot.
Affected software
TD220X
SD series radio firmware
iNET
iNET II
How to mitigate CVE-2022-24118
TD220X - update to 2.0.16
SD series radio firmware - update to 6.4.7
iNET - update to 8.3.0
iNET II - update to 8.3.0