CVE-2020-27149

MEDIUM

NPort IA5150A/IA5250A <1.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (3)
moxa/nport_ia5150a_firmware < 1.5
moxa/nport_ia5250a_firmware < 1.5
moxa/nport_ia5450a_firmware < 2.0
Published May 14, 2021
Tracked Since Feb 18, 2026