← Vulnerability feed

Vulnerability record · CVE-2022-40224 · published 7 February 2023

CVE-2022-40224: Moxa SDS-3008 web server denial of service via crafted HTTP header

Moxa · Sds 3008 Firmware

The web server in Moxa SDS-3008 Series Industrial Ethernet Switch firmware 2.1 mishandles a specially crafted HTTP message header, causing a denial of service. The flaw is remotely reachable over the network without authentication, so an unauthenticated attacker can take the switch's web interface down. Because these are industrial switches, loss of the management interface can disrupt monitoring and configuration of the device.

7.5 CVSS 3.1 High EPSS 65% · top 0.8% CWE-410 · CWE-410
7.5CVSS 3.1 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote denial of service on an industrial switch with a high EPSS score and public exploit detail, though no KEV listing or confirmed in-the-wild use.

What it is

The web server in Moxa SDS-3008 Series Industrial Ethernet Switch firmware 2.1 mishandles a specially crafted HTTP message header, causing a denial of service. The flaw is remotely reachable over the network without authentication, so an unauthenticated attacker can take the switch's web interface down. Because these are industrial switches, loss of the management interface can disrupt monitoring and configuration of the device.

Impact

An attacker can crash or hang the switch's web server, denying access to the management interface. The CVSS vector shows only availability impact (A:H) with no confidentiality or integrity loss.

Attack surface

Reached over the network via HTTP to the switch's web server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. The description confirms the trigger is a crafted HTTP request.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.647, 99.2nd percentile) and the Talos reference is tagged Exploit and Technical Description, indicating public technical detail exists. No confirmed in-the-wild exploitation is stated in the record.

What to do

  • Apply the Moxa security advisory fix for SDS-3008 Series firmware (upgrade from 2.1 to the patched release).
  • Restrict HTTP/HTTPS management access to trusted management networks or jump hosts via ACLs and firewall rules.
  • Disable the web management interface where it is not required.
  • Segment industrial switches from general IT and internet-facing networks to limit reachability.
  • Monitor vendor advisories for updated firmware and re-check exposure after patching.

Detection

  • Alert on repeated malformed or oversized HTTP header requests to the switch's web server.
  • Monitor for web server process restarts, crashes, or management interface unavailability on SDS-3008 devices.
  • Baseline and alert on unexpected source IPs reaching the switch management interface.
  • Correlate switch availability gaps with HTTP request logs or network flow anomalies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-40224), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.