Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.19% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iNET II before 8.3.0. | |
| Modificada | Crítica (9.8) | 0.74% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0. | |
| Modificada | Crítica (9.1) | 0.64% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory default configuration. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | |
| Modificada | Crítica (9.8) | 0.36% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0, SD before 6.4.7, TD220X before 2.0.16, and TD220MAX before 1.2.6. | |
| Modificada | Crítica (9.8) | 0.30% | — | GE Inet 900 FirmwareGE Inet II 900 FirmwareGE SD1 FirmwareGE SD2 Firmware+4 | 26/12/2022 | 17/6/2026 | Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II before 8.3.0. |