CVE-2022-40691
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 1.5%
exploitation probability
1.5%top 29% of all CVEs
observed exploitation
nono source reports it
In short
The Moxa SDS-3008 Series switch exposes sensitive information through specially-crafted HTTP requests. An attacker can retrieve this data without proper authentication or authorization.
Technical detail
An information disclosure vulnerability in the web application of Moxa SDS-3008 Series (v2.1) allows an unauthenticated attacker to craft specific HTTP requests that bypass access controls and leak sensitive information. The vulnerability requires network access to the web interface but no credentials, potentially exposing configuration, credentials, or operational data.
Summary generated and translated by AI from the official description.
An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Moxa · SDS-3008 Series Industrial Ethernet Switch