First published: Fri May 14 2021(Updated: )
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport Ia5150a Firmware | <1.5 | |
Moxa Nport Ia5150a | ||
Moxa Nport Ia5250a Firmware | <1.5 | |
Moxa Nport Ia5250a | ||
Moxa Nport Ia5450a Firmware | <2.0 | |
Moxa Nport Ia5450a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27149 is a vulnerability found in NPort IA5150A/IA5250A Series before version 1.5 that allows a user with 'Read Only' privilege level to change the device's configuration via the web console.
NPort IA5150A/IA5250A Series firmware versions up to (but not including) 1.5 are affected by CVE-2020-27149.
CVE-2020-27149 has a severity rating of 6.5 (medium).
To fix CVE-2020-27149, you should update the firmware of your NPort IA5150A/IA5250A Series device to version 1.5 or higher.
More information about CVE-2020-27149 can be found at the following references: [Kaspersky Advisory](https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/05/11/klcert-20-018) and [Moxa Security Advisory](https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities)