First published: Fri May 14 2021(Updated: )
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
Credit: vulnerability@kaspersky.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport Ia5150a Firmware | <=1.4 | |
Moxa Nport Ia5150a | ||
Moxa Nport Ia5250a Firmware | <=1.4 | |
Moxa Nport Ia5250a | ||
Moxa Nport Ia5450a Firmware | <=1.7 | |
Moxa Nport Ia5450a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27185 is a vulnerability that allows cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices.
CVE-2020-27185 has a severity of 7.5 (high).
CVE-2020-27185 affects Moxa NPort IA5150A firmware versions up to and including 1.4, and Moxa NPort IA5450A firmware versions up to and including 1.7.
CVE-2020-27185 can be exploited by attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
To fix CVE-2020-27185, it is recommended to update the affected Moxa NPort IA5000A series serial devices to a patched firmware version provided by Moxa.