CVE-2020-27185

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:nport_ia5150a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5150a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:moxa:nport_ia5250a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5250a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:moxa:nport_ia5450a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5450a:-:*:*:*:*:*:*:*

History

21 May 2021, 18:47

Type Values Removed Values Added
CPE cpe:2.3:o:moxa:nport_ia5250a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_ia5150a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5250a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_ia5450a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5150a:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_ia5450a:-:*:*:*:*:*:*:*
CWE CWE-319
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities - (MISC) https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities - Vendor Advisory
References (MISC) https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/05/11/klcert-20-021, - (MISC) https://ics-cert.kaspersky.com/advisories/klcert-advisories/2021/05/11/klcert-20-021, - Broken Link

Information

Published : 2021-05-14 13:15

Updated : 2024-02-04 21:47


NVD link : CVE-2020-27185

Mitre link : CVE-2020-27185

CVE.ORG link : CVE-2020-27185


JSON object : View

Products Affected

moxa

  • nport_ia5150a_firmware
  • nport_ia5250a
  • nport_ia5250a_firmware
  • nport_ia5450a_firmware
  • nport_ia5150a
  • nport_ia5450a
CWE
CWE-319

Cleartext Transmission of Sensitive Information