SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-27048

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device.

HIGH 7.4EPSS 0.80%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.

CVSS 3.1
7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
0.80% probability · 55th percentile
CISA KEV
Not listed
Affected
moxa/mgate mb3170i firmware · moxa/mgate mb3170i-t firmware · moxa/mgate mb3170-m-st firmware · moxa/mgate mb3170-m-sc-t firmware · moxa/mgate mb3170 firmware · moxa/mgate mb3170-t firmware · moxa/mgate mb3170-m-sc firmware · moxa/mgate mb3170i-s-sc firmware · moxa/mgate mb3270i firmware · moxa/mgate mb3270i-t firmware · moxa/mgate mb3170i-m-sc firmware · moxa/mgate mb3170-s-sc-t firmware · moxa/mgate mb3170i-m-sc-t firmware · moxa/mgate mb3270 firmware · moxa/mgate mb3270-t firmware · moxa/mgate mb3170-s-sc firmware · moxa/mgate mb3170-m-st-t firmware · moxa/mgate mb3170i-s-sc-t firmware · moxa/mgate mb3280 firmware · moxa/mgate mb3480 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.