CVE-2022-27048
Last modified
CVE-2022-27048 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Mgate Mb3170i Firmware | <= 4.2 |
| Moxa | Mgate Mb3170i-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-M-St Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-M-Sc-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170 Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-M-Sc Firmware | <= 4.2 |
| Moxa | Mgate Mb3170i-S-Sc Firmware | <= 4.2 |
| Moxa | Mgate Mb3270i Firmware | <= 4.2 |
| Moxa | Mgate Mb3270i-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170i-M-Sc Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-S-Sc-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170i-M-Sc-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3270 Firmware | <= 4.2 |
| Moxa | Mgate Mb3270-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-S-Sc Firmware | <= 4.2 |
| Moxa | Mgate Mb3170-M-St-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3170i-S-Sc-T Firmware | <= 4.2 |
| Moxa | Mgate Mb3280 Firmware | <= 4.1 |
| Moxa | Mgate Mb3480 Firmware | <= 3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27048?
How severe is CVE-2022-27048?
How do I fix CVE-2022-27048?
Are you affected by CVE-2022-27048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
