CVE-2022-24119
https://notcve.org/view.php?id=CVE-2022-24119
Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0. Ciertos productos de General Electric Renewable Energy tienen una función oculta para el acceso remoto no autenticado al shell de configuración del dispositivo. Esto afecta a iNET e iNET II anteriores a 8.3.0. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06 • CWE-829: Inclusion of Functionality from Untrusted Control Sphere •
CVE-2022-3092 – GE CIMPLICITY Out-of-bounds Write
https://notcve.org/view.php?id=CVE-2022-3092
GE CIMPICITY versions 2022 and prior is vulnerable to an out-of-bounds write, which could allow an attacker to execute arbitrary code. Las versiones 2022 y anteriores de GE CIMPICITY son vulnerables a una escritura fuera de los límites, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-787: Out-of-bounds Write •
CVE-2022-3084 – GE CIMPLICITY Access of Uninitialized Pointer
https://notcve.org/view.php?id=CVE-2022-3084
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiRootOptionTable, which could allow an attacker to execute arbitrary code. GE CIMPICITY versiones 2022 y anteriores es vulnerable cuando los datos de una dirección defectuosa controlan el flujo de código a partir de gmmiObj!CGmmiRootOptionTable, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-824: Access of Uninitialized Pointer •
CVE-2022-2952 – GE CIMPLICITY Access of Uninitialized Pointer
https://notcve.org/view.php?id=CVE-2022-2952
GE CIMPICITY versions 2022 and prior is vulnerable when data from a faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code. GE CIMPICITY versiones 2022 y anteriores es vulnerable cuando los datos de una dirección defectuosa controlan el flujo de código a partir de gmmiObj!CGmmiOptionContainer, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-824: Access of Uninitialized Pointer •
CVE-2022-2948 – GE CIMPLICITY Heap-based Buffer Overflow
https://notcve.org/view.php?id=CVE-2022-2948
GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to execute arbitrary code. Las versiones 2022 y anteriores de GE CIMPICITY son vulnerables a un desbordamiento de búfer de almacenamiento dinámico, lo que podría permitir a un atacante ejecutar código arbitrario. • https://www.cisa.gov/uscert/ics/advisories/icsa-22-326-04 • CWE-122: Heap-based Buffer Overflow •