PT-2022-10169 · Moxa · Moxa Nport Iaw5000A-I/O

Evgeniy Druzhinin

+2

·

Published

2022-04-01

·

Updated

2023-06-26

·

CVE-2021-32974

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa NPort IAW5000A-I/O series firmware versions 2.2 or earlier
Description The issue is related to improper input validation in the built-in web server, which may allow a remote attacker to execute commands.
Recommendations For Moxa NPort IAW5000A-I/O series firmware versions 2.2 or earlier, update to a version later than 2.2 to resolve the issue. As a temporary workaround, consider restricting access to the built-in web server until a patch is available.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-32974

Affected Products

Moxa Nport Iaw5000A-I/O