CVE-2020-27185
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Nport Ia5150a | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Nport Ia5250a | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.7 |
| Running on/with | Platform Versions |
|---|---|
Moxa Nport Ia5450a | All versions |
References (4)
Source: vulnerability@kaspersky.com
Source: vulnerability@kaspersky.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.