AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-30274

CRITICAL · CVSS 9.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-07-26 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.

CVE
CVE-2022-30274
Severity
CRITICAL
CVSS
9.8
EPSS
0.60%

Original NVD Description

The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.

Related CVEs

Other vulnerabilities affecting the same vendor(s)