Improper access control in Moxa products - CVE-2020-27149
Published: April 28, 2021 / Updated: May 12, 2021
Vulnerability identifier: #VU52686
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27149
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass implemented security restrictions and gain elevated privileges on the system.
Affected software
NPort IA5150A Series
NPort IA5250A Series
NPort IA5450A Series
NPort IA5250A Series
NPort IA5450A Series
How to mitigate CVE-2020-27149
Install updates from vendor's website.
NPort IA5150A Series - update to 1.5
NPort IA5250A Series - update to 1.5
NPort IA5450A Series - update to 2.0
NPort IA5250A Series - update to 1.5
NPort IA5450A Series - update to 2.0