CVE-2020-25190

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
23/12/2020
Last modified:
23/12/2020

Description

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:nport_iaw5000a-i\/o_firmware:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:h:moxa:nport_iaw5000a-i\/o:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools