First published: Fri May 01 2020(Updated: )
Moxa Service in Moxa NPort 5150A firmware version 1.5 and earlier allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800. NOTE: Moxa Service is an unauthenticated service that runs upon a first-time installation but can be disabled without ill effect.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport 5100a Firmware | <=1.5 | |
Moxa Nport 5100a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-12117 is medium with a CVSS score of 5.3.
CVE-2020-12117 allows attackers to obtain sensitive configuration values via a crafted packet to UDP port 4800.
Yes, Moxa NPort 5100A firmware version 1.5 is vulnerable to CVE-2020-12117.
Yes, the Moxa Service can be disabled without ill effect.
You can find more information about CVE-2020-12117 at the following references: [link1], [link2].