CVE-2022-38469
https://notcve.org/view.php?id=CVE-2022-38469
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. • https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 • CWE-261: Weak Encoding for Password CWE-522: Insufficiently Protected Credentials •
CVE-2022-46331
https://notcve.org/view.php?id=CVE-2022-46331
An unauthorized user could possibly delete any file on the system. • https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 • CWE-284: Improper Access Control •
CVE-2022-43494
https://notcve.org/view.php?id=CVE-2022-43494
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. • https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 • CWE-284: Improper Access Control •
CVE-2022-46660
https://notcve.org/view.php?id=CVE-2022-46660
An unauthorized user could alter or write files with full control over the path and content of the file. • https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-46732 – CVE-2022-46732
https://notcve.org/view.php?id=CVE-2022-46732
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. • https://digitalsupport.ge.com/s/article/GE-Digital-Product-Security-Advisory-GED-23-01 https://www.cisa.gov/uscert/ics/advisories/icsa-23-017-01 •