CVE-2020-27149: Medium severity moxa nport ia5150a-ie vulnerability
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27149?
CVE-2020-27149 is a vulnerability found in NPort IA5150A/IA5250A Series before version 1.5 that allows a user with 'Read Only' privilege level to change the device's configuration via the web console.
Which software versions are affected by CVE-2020-27149?
NPort IA5150A/IA5250A Series firmware versions up to (but not including) 1.5 are affected by CVE-2020-27149.
What is the severity of CVE-2020-27149?
CVE-2020-27149 has a severity rating of 6.5 (medium).
How can I fix CVE-2020-27149?
To fix CVE-2020-27149, you should update the firmware of your NPort IA5150A/IA5250A Series device to version 1.5 or higher.
Where can I find more information about CVE-2020-27149?
More information about CVE-2020-27149 can be found at the following references: [Kaspersky Advisory](https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/05/11/klcert-20-018) and [Moxa Security Advisory](https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities)