CVE-2022-3086
published 2022-12-02CVE-2022-3086: Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain…
PriorityP337high7.6CVSS 3.1
AVPACLPRNUINSCCHIHAH
EPSS
0.30%
22.0th percentile
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable
to shell escape, which enables local attackers with non-superuser
credentials to gain full, unrestrictive shell access which may allow an
attacker to execute arbitrary code.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cradlepoint | ibr600 | <= 6.5.0.160bc2e | — |
| moxa | uc-2101-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2102-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2104-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2111-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2112-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2114-t-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2116-t-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-3101-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3101-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3101-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-ap-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-eu-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-us-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-5101-lx_firmware | — | — |
| moxa | uc-5101-t-lx_firmware | — | — |
| moxa | uc-5102-lx_firmware | — | — |
| moxa | uc-5102-t-lx_firmware | — | — |
| moxa | uc-5111-lx_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Cradlepoint IBR600
cisa_ics·2022-11-21·CVSS 7.1
[HIGH] Cradlepoint IBR600
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Cradlepoint IBR600
Last RevisedNovember 21, 2022
Alert CodeICSA-22-321-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.1
- ATTENTION: Low attack complexity
- Vendor: Cradlepoint
- Equipment: IBR600
- Vulnerabilities: Command Injection
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute code and native system commands.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Cradlepoint IBR600 are affected:
- Cradlepoint IBR600 NetCloud OS (NCOS) Version: 6.5.0.160bc2e and prior
## 3.2 VULNERABILITY OVERVIEW
GHSA
GHSA-g37x-jpmr-w7p9: An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1
ghsa_unreviewed·2023-07-06
CVE-2022-3086 [HIGH] CWE-1263 GHSA-g37x-jpmr-w7p9: An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1
An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1.1, UC-8540 Series V1.0 to V1.2, UC-8410A Series V2.2, UC-8200 Series V1.0 to V2.4, UC-8100A-ME-T Series V1.0 to V1.1, UC-8100 Series V1.2 to V1.3, UC-5100 Series V1.2, UC-3100 Series V1.2 to V2.0, UC-2100 Series V1.3 to V1.5, and UC-2100-W Series V1.3 to V1.5 can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-02
Published