CVE-2022-43977
https://notcve.org/view.php?id=CVE-2022-43977
An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessible via TCP (a qconn service) lacks access control. • https://wid.cert-bund.de/.well-known/csaf/white/2022/bsi-2022-0005.json •
CVE-2022-43976
https://notcve.org/view.php?id=CVE-2022-43976
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct access to the API is possible on TCP port 8888 via programs located in the cgi-bin folder without any authentication. • https://wid.cert-bund.de/.well-known/csaf/white/2022/bsi-2022-0005.json •
CVE-2022-43975
https://notcve.org/view.php?id=CVE-2022-43975
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vulnerability in the web server allows arbitrary files and configurations to be read via directory traversal over TCP port 8888. • https://wid.cert-bund.de/.well-known/csaf/white/2022/bsi-2022-0005.json • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •