Configuration Change Vulnerability in NPort IA5150A/IA5250A Series by Moxa
CVE-2020-27149
6.5MEDIUM
Key Information:
- Vendor
- Moxa
- Vendor
- CVE Published:
- 14 May 2021
Summary
A security issue exists in Moxa's NPort IA5150A/IA5250A Series, allowing users with only 'Read Only' privileges to manipulate device configurations through the web console. This limitation in user role enforcement can lead to unauthorized changes to critical system settings, underscoring the need for reinforced access controls and prompt updates to maintain system integrity.
Affected Version(s)
NPort IA5000A Series with web console enabled All versions before 1.5 for NPort IA5150A/IA5250A Series. All version before 2.0 for NPort 5450 Series
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved