CVE-2022-3086

HIGHCVSS 7.6/10EPSS 0.30%

Last modified

CVE-2022-3086 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code. . EPSS estimates a 0.30% chance of exploitation in the next 30 days.

Description

Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.

Metrics

CVSS 3.1
7.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.30%

21.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MoxaUc-8580-T-Lx Firmware1.1
MoxaUc-8580-T-Ct-Lx Firmware1.1
MoxaUc-8580-T-Q-Lx Firmware1.1
MoxaUc-8580-T-Ct-Q-Lx Firmware1.1
MoxaUc-8580-Q-Lx Firmware1.1
MoxaUc-8580-Lx Firmware1.1
MoxaUc-8540-Lx Firmware>= 1.0, <= 1.2
MoxaUc-8540-T-Ct-Lx Firmware>= 1.0, <= 1.2
MoxaUc-8540-T-Lx Firmware>= 1.0, <= 1.2
MoxaUc-8410a-Lx Firmware2.2
MoxaUc-8410a-Nw-Lx Firmware2.2
MoxaUc-8410a-Nw-T-Lx Firmware2.2
MoxaUc-8410a-T-Lx Firmware2.2
MoxaUc-8210-T-Lx-S Firmware>= 1.0, <= 2.4
MoxaUc-8220-T-Lx Firmware>= 1.0, <= 2.4
MoxaUc-8220-T-Lx-Us-S Firmware>= 1.0, <= 2.4
MoxaUc-8220-T-Lx-Eu-S Firmware>= 1.0, <= 2.4
MoxaUc-8220-T-Lx-Ap-S Firmware>= 1.0, <= 2.4
MoxaUc-8112a-Me-T-Lx Firmware1.0
MoxaUc-8112a-Me-T-Lx Firmware1.1
MoxaUc-8131-Lx Firmware1.2
MoxaUc-8131-Lx Firmware1.3
MoxaUc-8132-Lx Firmware1.2
MoxaUc-8132-Lx Firmware1.3
MoxaUc-8162-Lx Firmware1.2
MoxaUc-8162-Lx Firmware1.3
MoxaUc-8112-Lx Firmware1.2
MoxaUc-8112-Lx Firmware1.3
MoxaUc-5101-Lx Firmware1.2
MoxaUc-5101-T-Lx Firmware1.2
MoxaUc-5102-Lx Firmware1.2
MoxaUc-5102-T-Lx Firmware1.2
MoxaUc-5111-Lx Firmware1.2
MoxaUc-5111-T-Lx Firmware1.2
MoxaUc-5112-Lx Firmware1.2
MoxaUc-5112-T-Lx Firmware1.2
MoxaUc-3101-T-Ap-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3101-T-Eu-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3101-T-Us-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Ap-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Ap-Lx-Nw Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Eu-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Eu-Lx-Nw Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Us-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3111-T-Us-Lx-Nw Firmware>= 1.2, <= 2.0
MoxaUc-3121-T-Ap-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3121-T-Eu-Lx Firmware>= 1.2, <= 2.0
MoxaUc-3121-T-Us-Lx Firmware>= 1.2, <= 2.0
MoxaUc-2101-Lx Firmware>= 1.3, <= 1.5
MoxaUc-2102-Lx Firmware>= 1.3, <= 1.5

Showing 50 of 55 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-3086?
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
How severe is CVE-2022-3086?
CVE-2022-3086 has a CVSS score of 7.6/10 (HIGH severity). The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3086?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-3086?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST