First published: Tue Jan 17 2023(Updated: )
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ge Ms 3000 Firmware | <3.7.6.25p0_3.2.2.17p0_4.7p0 | |
Ge Ms 3000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43976 is a vulnerability discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0.
The severity of CVE-2022-43976 is critical, with a severity value of 9.8.
CVE-2022-43976 allows direct access to the API on TCP port 8888 through programs located in the cgi-bin folder without any authentication.
GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0 are affected by CVE-2022-43976.
Yes, GE MS 3000 firmware versions before 3.7.6.25p0_3.2.2.17p0_4.7p0 are vulnerable to CVE-2022-43976.
To fix CVE-2022-43976, it is recommended to update GE MS 3000 firmware to version 3.7.6.25p0_3.2.2.17p0_4.7p0 or later.
You can find more information about CVE-2022-43976 at the following reference link: https://wid.cert-bund.de/.well-known/csaf/white/2022/bsi-2022-0005.json