First published: Fri Apr 15 2022(Updated: )
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Mgate Mb3170i Firmware | <=4.2 | |
Moxa Mgate Mb3170i | ||
Moxa Mgate Mb3170i-t Firmware | <=4.2 | |
Moxa Mgate Mb3170i-t | ||
Moxa Mgate Mb3170-m-st Firmware | <=4.2 | |
Moxa Mgate Mb3170-m-st | ||
Moxa Mgate Mb3170-m-sc-t Firmware | <=4.2 | |
Moxa Mgate Mb3170-m-sc-t | ||
Moxa Mgate Mb3170 Firmware | <=4.2 | |
Moxa Mgate Mb3170 | ||
Moxa Mgate Mb3170-t Firmware | <=4.2 | |
Moxa Mgate Mb3170-t | ||
Moxa Mgate Mb3170-m-sc Firmware | <=4.2 | |
Moxa Mgate Mb3170-m-sc | ||
Moxa Mgate Mb3170i-s-sc Firmware | <=4.2 | |
Moxa Mgate Mb3170i-s-sc | ||
Moxa Mgate Mb3270i Firmware | <=4.2 | |
Moxa Mgate Mb3270i | ||
Moxa Mgate Mb3270i-t Firmware | <=4.2 | |
Moxa Mgate Mb3270i-t | ||
Moxa Mgate Mb3170i-m-sc Firmware | <=4.2 | |
Moxa Mgate Mb3170i-m-sc | ||
Moxa Mgate Mb3170-s-sc-t Firmware | <=4.2 | |
Moxa Mgate Mb3170-s-sc-t | ||
Moxa Mgate Mb3170i-m-sc-t Firmware | <=4.2 | |
Moxa Mgate Mb3170i-m-sc-t | ||
Moxa Mgate Mb3270 Firmware | <=4.2 | |
Moxa Mgate Mb3270 | ||
Moxa Mgate Mb3270-t Firmware | <=4.2 | |
Moxa Mgate Mb3270-t | ||
Moxa Mgate Mb3170-s-sc Firmware | <=4.2 | |
Moxa Mgate Mb3170-s-sc | ||
Moxa Mgate Mb3170-m-st-t Firmware | <=4.2 | |
Moxa Mgate Mb3170-m-st-t | ||
Moxa Mgate Mb3170i-s-sc-t Firmware | <=4.2 | |
Moxa Mgate Mb3170i-s-sc-t | ||
Moxa Mgate Mb3280 Firmware | <=4.1 | |
Moxa Mgate Mb3280 | ||
Moxa Mgate Mb3480 Firmware | <=3.2 | |
Moxa Mgate Mb3480 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27048 is a vulnerability in Moxa MGate that allows for a man-in-the-middle attack on the device.
MGate MB3170 Series Firmware Version 4.2 or lower, MGate MB3270 Series Firmware Version 4.2 or lower, and MGate MB3280 Series Firmware Version 4.1 or lower are affected.
CVE-2022-27048 has a severity rating of 7.4 (High).
Update Moxa MGate to a version higher than 4.2 for MB3170 and MB3270 series, or higher than 4.1 for MB3280 series.
You can find more information about CVE-2022-27048 on the Moxa website at the following link: https://www.moxa.com/en/support/product-support/security-advisory/mgate-mb3170-mb3270-mb3280-mb3480-protocol-gateways-vulnerability