PT-2021-3065 · Moxa · Nport Ia5150A+3

Alexander Nochvay

·

Published

2021-04-28

·

Updated

2021-05-24

·

CVE-2020-27150

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions NPort IA5150A/IA5250A, IA5450A versions (affected versions not specified) NPort IA5000A Series versions (affected versions not specified)
Description The issue is related to the storage of passwords in plaintext. This could allow a remote attacker to gain unauthorized access to sensitive information. The export of a device's configuration may contain user passwords and other sensitive data in their original form if a pre-shared key is not set.
Recommendations For NPort IA5150A/IA5250A, IA5450A, consider setting a pre-shared key to protect sensitive data. For NPort IA5000A Series, set a pre-shared key to prevent the export of sensitive data in plaintext. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02677
CVE-2020-27150

Affected Products

Nport Ia5000A Series
Nport Ia5150A
Nport Ia5250A
Nport Ia5450A