CVE-2022-30276

7.5
HIGHCVSS v3.1 Base Score
0.82%
LOW RiskEPSS (56th percentile)

The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with RTUs behind the gateway is done by means of the proprietary IPGW protocol (5001/TCP). This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

Published: 7/26/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Score (Exploitation Probability)

0.82%LOW Exploitation Risk
56th percentile

This vulnerability has a 0.82% probability of being exploited in the next 30 days, ranking higher than 56% of all scored CVEs.

CWE Classification

Advertisement