CVE-2020-27185

HIGH

Moxa NPort IA5000A Series < 1.4/1.7 - Cleartext Transmission of Sensitive Information via Moxa Service

Title source: llm
STIX 2.1

Description

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319
Status published
Products (3)
moxa/nport_ia5150a_firmware < 1.4
moxa/nport_ia5250a_firmware < 1.4
moxa/nport_ia5450a_firmware < 1.7
Published May 14, 2021
Tracked Since Feb 18, 2026