CVE-2020-25194
published 2020-12-23CVE-2020-25194: The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.03%
59.9th percentile
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | nport_iaw5000a-i_o | unspecified – Version 2.1 | — |
| moxa | nport_iaw5000a-i_o_firmware | <= 2.1 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
MOXA NPort IAW5000A-I/O Series
cisa_ics·2020-10-13·CVSS 8.8
[HIGH] MOXA NPort IAW5000A-I/O Series
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
MOXA NPort IAW5000A-I/O Series
Last RevisedOctober 13, 2020
Alert CodeICSA-20-287-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: MOXA
- Equipment: NPort IAW5000A-I/O Series
- Vulnerabilities: Session Fixation, Improper Privilege Management, Weak Password Requirements, Cleartext Transmission of Sensitive Information, Improper Restriction of Excessive Authentication Attempts, Exposure of Sensitive Information to an Unauthorized Actor
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could a
GHSA
GHSA-rq59-f4hv-p8wv: The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2
ghsa_unreviewed·2022-05-24
CVE-2020-25194 [HIGH] CWE-269 GHSA-rq59-f4hv-p8wv: The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-23
Published