Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.18% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0. | |
| Modificada | Crítica (9.8) | 0.72% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0. | |
| Modificada | Crítica (9.1) | 0.63% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | |
| Modificada | Crítica (9.8) | 0.35% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | |
| Modificada | Crítica (9.8) | 0.29% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. |