CVE-2022-3088
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.
Affected (75)
Products: Moxa: Uc 2101 Lx Firmware, Uc 2102 Lx Firmware, Uc 2104 Lx Firmware, Uc 2111 Lx Firmware, Uc 2112 Lx Firmware, Uc 2102 T Lx Firmware, Uc 2114 T Lx Firmware, Uc 2116 T Lx Firmware, Uc 3101 T Us Lx Firmware, Uc 3101 T Eu Lx Firmware, Uc 3111 T Us Lx Firmware, Uc 3111 T Eu Lx Firmware, Uc 3121 T Us Lx Firmware, Uc 3121 T Eu Lx Firmware, Uc 3101 T Ap Lx Firmware, Uc 3111 T Ap Lx Firmware, Uc 3121 T Ap Lx Firmware, Uc 3111 T Eu Lx Nw Firmware, Uc 3111 T Ap Lx Nw Firmware, Uc 3111 T Us Lx Nw Firmware, Uc 5101 Lx Firmware, Uc 5101 T Lx Firmware, Uc 5102 Lx Firmware, Uc 5102 T Lx Firmware, Uc 5111 Lx Firmware, Uc 5111 T Lx Firmware, Uc 5112 Lx Firmware, Uc 5112 T Lx Firmware, Uc 8131 Lx Firmware, Uc 8132 Lx Firmware, Uc 8162 Lx Firmware, Uc 8112 Lx Firmware, Uc 8112 Me T Lx1 Firmware, Uc 8112 Me T Lx Firmware, Uc 8112a Me T Lx Firmware, Uc 8220 T Lx S Firmware, Uc 8220 T Lx Firmware, Uc 8220 T Lx Us S Firmware, Uc 8220 T Lx Eu S Firmware, Uc 8220 T Lx Ap S Firmware, Aig 301 T Us Azu Lx Firmware, Aig 301 T Eu Azu Lx Firmware, Aig 301 T Ap Azu Lx Firmware, Aig 301 T Cn Azu Lx Firmware, Aig 301 T Azu Lx Firmware, Aig 301 Azu Lx Firmware, Aig 301 Us Azu Lx Firmware, Aig 301 Eu Azu Lx Firmware, Aig 301 Ap Azu Lx Firmware, Aig 301 Cn Azu Lx Firmware, Uc 8410a Lx Firmware, Uc 8410a T Lx Firmware, Uc 8410a Nw Lx Firmware, Uc 8410a Nw T Lx Firmware, Uc 8580 Lx Firmware, Uc 8580 T Lx Firmware, Uc 8580 T Ct Lx Firmware, Uc 8580 Q Lx Firmware, Uc 8580 T Q Lx Firmware, Uc 8580 T Ct Q Lx Firmware, Uc 8540 Lx Firmware, Uc 8540 T Lx Firmware, Uc 8540 T Ct Lx Firmware, Da 662c 16 Lx Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.12 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2101 Lx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2102 Lx | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2104 Lx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2111 Lx | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2112 Lx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2102 T Lx | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2114 T Lx | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 2116 T Lx | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3101 T Us Lx | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3101 T Eu Lx | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Us Lx | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Eu Lx | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3121 T Us Lx | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3121 T Eu Lx | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3101 T Ap Lx | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Ap Lx | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3121 T Ap Lx | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Eu Lx Nw | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Ap Lx Nw | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 3111 T Us Lx Nw | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5101 Lx | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5101 T Lx | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5102 Lx | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5102 T Lx | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5111 Lx | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5111 T Lx | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5112 Lx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 5112 T Lx | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8131 Lx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8132 Lx | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8162 Lx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 3.0 to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8112 Lx | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8112 Me T Lx1 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8112 Me T Lx | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8112a Me T Lx | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8220 T Lx S | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8220 T Lx | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8220 T Lx Us S | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8220 T Lx Eu S | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8220 T Lx Ap S | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 T Us Azu Lx | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 T Eu Azu Lx | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 T Ap Azu Lx | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 T Cn Azu Lx | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 T Azu Lx | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 Azu Lx | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 Us Azu Lx | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 Eu Azu Lx | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 Ap Azu Lx | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0 to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Aig 301 Cn Azu Lx | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.2 to 4.1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8410a Lx | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.2 to 4.1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8410a T Lx | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.2 to 4.1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8410a Nw Lx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.0.2 to 4.1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8410a Nw T Lx | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 Lx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 T Lx | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 T Ct Lx | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 Q Lx | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 T Q Lx | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8580 T Ct Q Lx | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8540 Lx | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Moxa Uc 8540 T Lx | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0 |
| Running on/with | Platform Versions |
|---|---|
Debian Debian Linux | Version 9.0 |
Moxa Uc 8540 T Ct Lx | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.0.2 to 1.1.2 |
| Running on/with | Platform Versions |
|---|---|
Moxa Da 662c 16 Lx | All versions |
Related CWEs
CWE-250
Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.