CVE Database
/

CVE-2022-3088

Back to search

CVE-2022-3088

Published: Nov 22, 2022

Modified: Apr 16, 2025

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.

VendorProductVersions

Moxa

UC-8100A-ME-T System Imaage

affected
1.0 - <= 1.6

Moxa

UC-2100 System Image

affected
1.0 - <= 1.12

Moxa

UC-2100-W System Image

affected
1.0 - <= 1.12

Moxa

UC-3100 System Image

affected
1.0 - <= 1.6

Moxa

UC-5100 System Image

affected
1.0 - <= 1.4

Moxa

UC-8100 System Image

affected
3.0 - <= 3.5

Moxa

UC-8100-ME-T System Image

affected
3.0 - <= 3.1

Moxa

UC-8200 System Image

affected
1.0 - <= 1.5

Moxa

AIG-300 System Image

affected
1.0 - <= 1.4

Moxa

UC-8410A with Debian 9 System Image

affected
4.0.2 and 4.1.2

Moxa

UC-8580 with Debian 9 System Image

affected
2.0 and 2.1

Moxa

UC-8540 with Debian 9 System Image

affected
2.0 and 2.1

Moxa

DA-662C-16-LX (GLB) System Image

affected
1.0.2 - <= 1.1.2

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now