SB2020082508 - Multiple vulnerabilities in Moxa NPort IAW5000A-I/O Series



SB2020082508 - Multiple vulnerabilities in Moxa NPort IAW5000A-I/O Series

Published: August 25, 2020 Updated: October 14, 2020

Security Bulletin ID SB2020082508
Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 secuirty vulnerabilities.


1) Session Fixation (CVE-ID: CVE-2020-25198)

The vulnerability allows a remote attacker to gain access to sensitive information on the system.

The vulnerability exists due to the session invalidation issue. A remote attacker can gain access to a session and hijack the session by stealing the user’s cookies.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-25194)

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.


3) Weak password requirements (CVE-ID: CVE-2020-25153)

The vulnerability allows an attacker to perform brute-force attack and guess the password.

The vulnerability exists due to weak password requirements. A remote authenticated attacker can perform a brute-force attack and guess users' passwords.


4) Cleartext transmission of sensitive information (CVE-ID: CVE-2020-25190)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A remote attacker with ability to intercept network traffic can gain access to sensitive data.


5) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2020-25196)

The vulnerability allows a remote attacker to gain access to the system.

The vulnerability exists due to the authentication mechanism has no brute-force prevention. A remote attacker can launch a brute-force authentication attack and gain access to the target system.


6) Information disclosure (CVE-ID: CVE-2020-25192)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the built-in web service. A remote attacker can gain unauthorized access to sensitive information on the system.


Remediation

Install update from vendor's website.