Vulnerability record · CVE-2022-40224 · published 7 February 2023
CVE-2022-40224: Moxa SDS-3008 web server denial of service via crafted HTTP header
Moxa · Sds 3008 Firmware
The web server in Moxa SDS-3008 Series Industrial Ethernet Switch firmware 2.1 mishandles a specially crafted HTTP message header, causing a denial of service. The flaw is remotely reachable over the network without authentication, so an unauthenticated attacker can take the switch's web interface down. Because these are industrial switches, loss of the management interface can disrupt monitoring and configuration of the device.
Description
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service on an industrial switch with a high EPSS score and public exploit detail, though no KEV listing or confirmed in-the-wild use.
What it is
The web server in Moxa SDS-3008 Series Industrial Ethernet Switch firmware 2.1 mishandles a specially crafted HTTP message header, causing a denial of service. The flaw is remotely reachable over the network without authentication, so an unauthenticated attacker can take the switch's web interface down. Because these are industrial switches, loss of the management interface can disrupt monitoring and configuration of the device.
Impact
An attacker can crash or hang the switch's web server, denying access to the management interface. The CVSS vector shows only availability impact (A:H) with no confidentiality or integrity loss.
Attack surface
Reached over the network via HTTP to the switch's web server; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. The description confirms the trigger is a crafted HTTP request.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.647, 99.2nd percentile) and the Talos reference is tagged Exploit and Technical Description, indicating public technical detail exists. No confirmed in-the-wild exploitation is stated in the record.
What to do
- Apply the Moxa security advisory fix for SDS-3008 Series firmware (upgrade from 2.1 to the patched release).
- Restrict HTTP/HTTPS management access to trusted management networks or jump hosts via ACLs and firewall rules.
- Disable the web management interface where it is not required.
- Segment industrial switches from general IT and internet-facing networks to limit reachability.
- Monitor vendor advisories for updated firmware and re-check exposure after patching.
Detection
- Alert on repeated malformed or oversized HTTP header requests to the switch's web server.
- Monitor for web server process restarts, crashes, or management interface unavailability on SDS-3008 devices.
- Baseline and alert on unexpected source IPs reaching the switch management interface.
- Correlate switch availability gaps with HTTP request logs or network flow anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1618 | ExploitTechnical DescriptionThird Party Advisory |
| https://www.moxa.com/en/support/product-support/security-advisory/sds-3008-series-multiple-web-vulnerabilities | Vendor Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2022-1618 | ExploitTechnical DescriptionThird Party Advisory |
| https://www.moxa.com/en/support/product-support/security-advisory/sds-3008-series-multiple-web-vulnerabilities | Vendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1618 |
Track CVE-2022-40224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-40224), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.