CVE-2022-43975: Path Traversal
Published Jan 17, 2023
·Updated
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p03.2.2.17p04.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.
Affected Software
4 affected components
GE Ms 3000 Firmware<3.7.6.25p0_3.2.2.17p0_4.7p0
GE Ms 3000
All of the following
GE Ms 3000 Firmware<3.7.6.25p0_3.2.2.17p0_4.7p0
GE Ms 3000
Event History
Jan 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-43975.
2
What is the severity of CVE-2022-43975?
The severity of CVE-2022-43975 is high with a score of 7.5.
3
What is the affected software for CVE-2022-43975?
The affected software for CVE-2022-43975 is GE Grid Solutions MS3000 devices before version 3.7.6.25p0_3.2.2.17p0_4.7p0.
4
How does CVE-2022-43975 impact the system?
CVE-2022-43975 allows arbitrary files and configurations to be read via directory traversal over TCP port 8888.
5
Is GE Ms 3000 firmware version 3.7.6.25p0_3.2.2.17p0_4.7p0 vulnerable?
Yes, GE Ms 3000 firmware version 3.7.6.25p0_3.2.2.17p0_4.7p0 is vulnerable to CVE-2022-43975.