Download of code without integrity check in General Electric Company products - CVE-2022-24117
Published: April 4, 2022
Vulnerability identifier: #VU61821
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24117
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system
The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote administrator gain full control over the affected system after a successful software update.
Affected software
TD220MAX
TD220X
SD series radio firmware
iNET
iNET II
TD220X
SD series radio firmware
iNET
iNET II
How to mitigate CVE-2022-24117
Install updates from vendor's website.
TD220MAX - update to 1.2.6
TD220X - update to 2.0.16
SD series radio firmware - update to 6.4.7
iNET - update to 8.3.0
iNET II - update to 8.3.0
TD220X - update to 2.0.16
SD series radio firmware - update to 6.4.7
iNET - update to 8.3.0
iNET II - update to 8.3.0