CVE-2020-25198

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/12/2020
Last modified:
23/12/2020

Description

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:nport_iaw5000a-i\/o_firmware:*:*:*:*:*:*:*:* 2.1 (including)
cpe:2.3:h:moxa:nport_iaw5000a-i\/o:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools