CVE-2022-40693: Moxa Sds-3008-T Firmware

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

Affected products

  • Moxa Sds-3008-T Firmware: up to and including 2.1
  • Moxa Sds-3008 Firmware: up to and including 2.1

Published 2023-02-07. Last modified 2026-06-17.