CVE-2022-30276: High severity motorola moscad ip gateway firmware vulnerability
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30276?
CVE-2022-30276 is a vulnerability in the Motorola MOSCAD and ACE line of RTUs that allows unauthorized access due to the omission of an authentication requirement.
How does CVE-2022-30276 impact systems?
CVE-2022-30276 allows attackers to gain unauthorized access to the affected systems.
What is the severity of CVE-2022-30276?
CVE-2022-30276 has a severity rating of 7.5 (high).
Which software is affected by CVE-2022-30276?
CVE-2022-30276 affects the Motorola MOSCAD and ACE line of RTUs with specific firmware versions.
How can CVE-2022-30276 be fixed?
To mitigate CVE-2022-30276, it is recommended to apply the necessary firmware updates provided by Motorola.