CVE-2022-27048
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- moxa/mgate mb3170i firmware · moxa/mgate mb3170i-t firmware · moxa/mgate mb3170-m-st firmware · moxa/mgate mb3170-m-sc-t firmware · moxa/mgate mb3170 firmware · moxa/mgate mb3170-t firmware · moxa/mgate mb3170-m-sc firmware · moxa/mgate mb3170i-s-sc firmware · moxa/mgate mb3270i firmware · moxa/mgate mb3270i-t firmware · moxa/mgate mb3170i-m-sc firmware · moxa/mgate mb3170-s-sc-t firmware · moxa/mgate mb3170i-m-sc-t firmware · moxa/mgate mb3270 firmware · moxa/mgate mb3270-t firmware · moxa/mgate mb3170-s-sc firmware · moxa/mgate mb3170-m-st-t firmware · moxa/mgate mb3170i-s-sc-t firmware · moxa/mgate mb3280 firmware · moxa/mgate mb3480 firmware
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.