PT-2020-3698 · Moxa · Moxa Nport Iaw5000A-I/O

Evgeniy Druzhinin

+1

·

Published

2020-05-26

·

Updated

2020-12-23

·

CVE-2020-25196

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MOXA NPort IAW5000A-I/O firmware versions 2.1 and lower
Description The issue is related to the implementation of SSH/Telnet protocols in the MOXA NPort IAW5000A-I/O Series web server software, which lacks sufficient restrictions on authentication attempts. This may allow a remote attacker to bypass security restrictions through brute force attacks.
Recommendations For MOXA NPort IAW5000A-I/O firmware versions 2.1 and lower, consider restricting or disabling SSH/Telnet sessions as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04053
CVE-2020-25196

Affected Products

Moxa Nport Iaw5000A-I/O