CVE-2020-27185

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
14/05/2021
Last modified:
07/11/2023

Description

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:nport_ia5150a_firmware:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:h:moxa:nport_ia5150a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_ia5250a_firmware:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:h:moxa:nport_ia5250a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_ia5450a_firmware:*:*:*:*:*:*:*:* 1.7 (including)
cpe:2.3:h:moxa:nport_ia5450a:-:*:*:*:*:*:*:*