VYPR
Unrated severityNVD Advisory· Published Nov 22, 2022· Updated Apr 16, 2025

CVE-2022-3088

CVE-2022-3088

Description

UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

16
  • Range: >=v1.0 <=v1.6
  • Moxa/UC-2100llm-create
    Range: >=v1.0 <=v1.12
  • Moxa/AIG-300llm-create
    Range: >=v1.0 <=v1.4
  • Moxa/AIG-300 System Imagev5
    Range: 1.0
  • Moxa/DA-662C-16-LX (GLB) System Imagev5
    Range: 1.0.2
  • Moxa/UC-2100 System Imagev5
    Range: 1.0
  • Moxa/UC-2100-W System Imagev5
    Range: 1.0
  • Moxa/UC-3100 System Imagev5
    Range: 1.0
  • Moxa/UC-5100 System Imagev5
    Range: 1.0
  • Moxa/UC-8100A-ME-T System Imaagev5
    Range: 1.0
  • Moxa/UC-8100-ME-T System Imagev5
    Range: 3.0
  • Moxa/UC-8100 System Imagev5
    Range: 3.0
  • Moxa/UC-8200 System Imagev5
    Range: 1.0
  • Moxa/UC-8410A with Debian 9 System Imagev5
    Range: 4.0.2 and 4.1.2
  • Moxa/UC-8540 with Debian 9 System Imagev5
    Range: 2.0 and 2.1
  • Moxa/UC-8580 with Debian 9 System Imagev5
    Range: 2.0 and 2.1

Patches

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.