CVE-2022-43976: Critical severity ge ms 3000 firmware vulnerability
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p03.2.2.17p04.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43976?
CVE-2022-43976 is a vulnerability discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0.
What is the severity of CVE-2022-43976?
The severity of CVE-2022-43976 is critical, with a severity value of 9.8.
How does CVE-2022-43976 affect GE Grid Solutions MS3000 devices?
CVE-2022-43976 allows direct access to the API on TCP port 8888 through programs located in the cgi-bin folder without any authentication.
Which software versions are affected by CVE-2022-43976?
GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0 are affected by CVE-2022-43976.
Is GE MS 3000 firmware vulnerable to CVE-2022-43976?
Yes, GE MS 3000 firmware versions before 3.7.6.25p0_3.2.2.17p0_4.7p0 are vulnerable to CVE-2022-43976.
Is there a fix available for CVE-2022-43976?
To fix CVE-2022-43976, it is recommended to update GE MS 3000 firmware to version 3.7.6.25p0_3.2.2.17p0_4.7p0 or later.
Where can I find more information about CVE-2022-43976?
You can find more information about CVE-2022-43976 at the following reference link: https://wid.cert-bund.de/.well-known/csaf/white/2022/bsi-2022-0005.json