CVE-2020-12117: Medium severity moxa nport 5100a series firmware vulnerability
Published May 1, 2020
·Updated
Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthenticated service that runs upon a first-time installation but can be disabled without ill effect.
Affected Software
2 affected components
MOXA Nport 5100a Firmware<=1.5
MOXA Nport 5100a
Remediation
Event History
May 1, 2020
CVE Published
via MITRE·01:41 PM
Data Sourced
via MITRE·01:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12117?
The severity of CVE-2020-12117 is medium with a CVSS score of 5.3.
2
How does CVE-2020-12117 impact Moxa NPort 5150A firmware version 1.5 and earlier?
CVE-2020-12117 allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800.
3
Is Moxa NPort 5100A firmware version 1.5 vulnerable to CVE-2020-12117?
Yes, Moxa NPort 5100A firmware version 1.5 is vulnerable to CVE-2020-12117.
4
Can the Moxa Service that runs on Moxa NPort 5150A firmware version 1.5 be disabled?
Yes, the Moxa Service can be disabled without ill effect.
5
Where can I find more information about CVE-2020-12117?
You can find more information about CVE-2020-12117 at the following references: [link1], [link2].