Unprotected storage of credentials in Moxa products - CVE-2020-27150
Published: April 28, 2021 / Updated: May 12, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to unprotected storage of credentials. A remote attacker can extract authentication credentials from a configuration file sent over an insecure communication channel and change the device’s configurations.
Affected software
NPort IA5250A Series
NPort IA5450A Series
How to mitigate CVE-2020-27150
NPort IA5250A Series - update to 1.5
NPort IA5450A Series - update to 2.0