SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27184

Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.

MEDIUM 5.9EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
moxa/nport ia5150a firmware · moxa/nport ia5250a firmware · moxa/nport ia5450a firmware
Source
vulnerability@kaspersky.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.