Credentials Management Vulnerability in Moxa NPort Wireless Devices
CVE-2017-16727

9.1CRITICAL

Key Information:

Vendor
Moxa
Vendor
CVE Published:
22 December 2017

Summary

A significant vulnerability has been identified in the Moxa NPort W2150A and W2250A devices, where the default credentials are set to an empty password. This flaw allows unauthorized users to access the device without any password protection, which poses a severe risk to the confidentiality and integrity of the data transmitted wirelessly. Without proper safeguards, this vulnerability exposes sensitive information to potential interception and manipulation, leading to comprehensive security breaches.

Affected Version(s)

Moxa NPort W2150A and W2250A Moxa NPort W2150A and W2250A

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.