First published: Fri May 14 2021(Updated: )
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport Ia5150a Firmware | <=1.4 | |
Moxa Nport Ia5150a | ||
Moxa Nport Ia5250a Firmware | <=1.4 | |
Moxa Nport Ia5250a | ||
Moxa Nport Ia5450a Firmware | <=1.7 | |
Moxa Nport Ia5450a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27150 is a vulnerability found in multiple versions of NPort IA5000A Series serial device servers.
CVE-2020-27150 has a severity rating of 7.5 (High).
Multiple versions of NPort IA5000A Series serial device servers are affected by CVE-2020-27150.
CVE-2020-27150 could result in the exposure of passwords of all users on the system and other sensitive data in the original form.
To fix CVE-2020-27150, ensure that the "Pre-shared key" is properly set in the device's configuration.