First published: Fri May 14 2021(Updated: )
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa NPort IA5150A-IE | <=1.4 | |
Moxa NPort IA5150A Firmware | ||
Moxa NPort IA5250A Firmware | <=1.4 | |
Moxa NPort IA5250A Firmware | ||
Moxa NPort IA5450A-T Firmware | <=1.7 | |
Moxa NPort IA5450A Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27150 is a vulnerability found in multiple versions of NPort IA5000A Series serial device servers.
CVE-2020-27150 has a severity rating of 7.5 (High).
Multiple versions of NPort IA5000A Series serial device servers are affected by CVE-2020-27150.
CVE-2020-27150 could result in the exposure of passwords of all users on the system and other sensitive data in the original form.
To fix CVE-2020-27150, ensure that the "Pre-shared key" is properly set in the device's configuration.