Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2020-17881 | The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext. | 
Solution
Moxa has released an updated firmware version (https://www.moxa.com/en/support/product-support/software-and-documentation/search?psid=50535) for the NPort IAW5000A-I/O Series and recommends (https://www.moxa.com/en/support/support/security-advisory/nport-iaw5000a-io-serial-device-servers-vulnerabilities) users install this update on all affected systems.
Workaround
No workaround given by the vendor.
| Link | Providers | 
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsa-20-287-01 |     | 
No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-16T21:08:02.611Z
Reserved: 2020-09-04T00:00:00
Link: CVE-2020-25190
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-12-23T15:15:15.517
Modified: 2024-11-21T05:17:36.083
Link: CVE-2020-25190
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.