← back
CVE-2022-40224mediumCWE-410

CVE-2022-40224

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 65%
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Moxa SDS-3008 switches allows an attacker to crash the web server by sending a specially crafted HTTP request header. This can temporarily disable access to the device's management interface.

Technical detail

The vulnerability exists in the HTTP message parsing logic of the web server in Moxa SDS-3008 Series firmware 2.1. A malformed HTTP header can trigger a denial of service condition, requiring an attacker to have network access to the device's web interface (CWE-410: Improper Restriction of Rendered UI Layers or Frames).

Summary generated and translated by AI from the official description.
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L