HIGH · 7.4

CVE-2022-27048

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. a...

Vulnerability Description

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
MoxaMgate Mb3170I Firmware<= 4.2
MoxaMgate Mb3170I-
MoxaMgate Mb3170I-T Firmware<= 4.2
MoxaMgate Mb3170I-T-
MoxaMgate Mb3170-M-St Firmware<= 4.2
MoxaMgate Mb3170-M-St-
MoxaMgate Mb3170-M-Sc-T Firmware<= 4.2
MoxaMgate Mb3170-M-Sc-T-
MoxaMgate Mb3170 Firmware<= 4.2
MoxaMgate Mb3170-
MoxaMgate Mb3170-T Firmware<= 4.2
MoxaMgate Mb3170-T-
MoxaMgate Mb3170-M-Sc Firmware<= 4.2
MoxaMgate Mb3170-M-Sc-
MoxaMgate Mb3170I-S-Sc Firmware<= 4.2
MoxaMgate Mb3170I-S-Sc-
MoxaMgate Mb3270I Firmware<= 4.2
MoxaMgate Mb3270I-
MoxaMgate Mb3270I-T Firmware<= 4.2
MoxaMgate Mb3270I-T-

References

FAQ

What is CVE-2022-27048?

CVE-2022-27048 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. a...

How severe is CVE-2022-27048?

CVE-2022-27048 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-27048?

Check the references section above for vendor advisories and patch information. Affected products include: Moxa Mgate Mb3170I Firmware, Moxa Mgate Mb3170I, Moxa Mgate Mb3170I-T Firmware, Moxa Mgate Mb3170I-T, Moxa Mgate Mb3170-M-St Firmware.