Resource exhaustion in General Electric Company products - CVE-2022-24118

 

Resource exhaustion in General Electric Company products - CVE-2022-24118

Published: April 4, 2022


Vulnerability identifier: #VU61819
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24118
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker on the local network can use the authentication code to cause affected series radios to reset back to the factory default configuration and reboot.


Affected software

TD220MAX
TD220X
SD series radio firmware
iNET
iNET II

How to mitigate CVE-2022-24118

Install updates from vendor's website.

TD220MAX - update to 1.2.6
TD220X - update to 2.0.16
SD series radio firmware - update to 6.4.7
iNET - update to 8.3.0
iNET II - update to 8.3.0

External References

Related Security Bulletins