The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-17885 The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
Fixes

Solution

Moxa has released an updated firmware version (https://www.moxa.com/en/support/product-support/software-and-documentation/search?psid=50535) for the NPort IAW5000A-I/O Series and recommends (https://www.moxa.com/en/support/support/security-advisory/nport-iaw5000a-io-serial-device-servers-vulnerabilities) users install this update on all affected systems.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T18:29:02.424Z

Reserved: 2020-09-04T00:00:00

Link: CVE-2020-25194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-23T15:15:15.730

Modified: 2024-11-21T05:17:36.780

Link: CVE-2020-25194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.