PT-2021-3066 · Moxa · Nport Ia5150A/Ia5250A Series

Alexander Nochvay

·

Published

2021-04-28

·

Updated

2021-05-21

·

CVE-2020-27149

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions NPort IA5150A/IA5250A Series versions prior to 1.5
Description The issue is related to inadequate access control in the NPort IA5150A/IA5250A Series, allowing a user with "Read Only" privilege level to send requests via the web console to change the device's configuration. This can be exploited by a remote attacker to bypass existing security restrictions and elevate their privileges.
Recommendations For versions prior to 1.5, update to version 1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the web console to prevent unauthorized configuration changes.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02678
CVE-2020-27149

Affected Products

Nport Ia5150A/Ia5250A Series