VYPR
Unrated severityNVD Advisory· Published Apr 15, 2022· Updated Aug 3, 2024

CVE-2022-27048

CVE-2022-27048

Description

An unauthenticated attacker can perform a man-in-the-middle attack on Moxa MGate protocol gateways by exploiting a channel accessible by non-endpoint vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated attacker can perform a man-in-the-middle attack on Moxa MGate protocol gateways by exploiting a channel accessible by non-endpoint vulnerability.

Vulnerability

A vulnerability exists in Moxa MGate MB3170, MB3270, MB3280, MB3480, and MB3660 series protocol gateways due to a channel accessible by non-endpoint weakness (CWE-300). This allows an attacker to perform a man-in-the-middle (MITM) attack on the device. The affected firmware versions are: MGate MB3170 Series firmware version 4.2 or lower, MGate MB3270 Series firmware version 4.2 or lower, MGate MB3280 Series firmware version 4.1 or lower, MGate MB3480 Series firmware version 3.2 or lower, and MGate MB3660 Series firmware version 2.5 or lower [1].

Exploitation

An attacker with network access to the affected gateway can exploit this vulnerability without requiring authentication. The attacker can position themselves between the gateway and legitimate endpoints to intercept, modify, or relay communications. No user interaction or special privileges are needed beyond being on the same network segment [1].

Impact

Successful exploitation enables the attacker to perform a man-in-the-middle attack, which can lead to the disclosure or manipulation of sensitive data transmitted through the gateway, as well as potential disruption of industrial control communications. The compromise occurs at the network level, allowing the attacker to act as an intermediary between devices [1].

Mitigation

Moxa has released firmware updates to address this vulnerability. The solutions are: upgrade MGate MB3170 Series to firmware version 4.3 or later, MGate MB3270 Series to firmware version 4.3 or later, MGate MB3280 Series to firmware version 4.2 or later, MGate MB3480 Series to firmware version 4.1 or later, and MGate MB3660 Series to firmware version 2.6 or later [1]. No workarounds are documented; the recommended action is to apply the available firmware updates.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.