SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27185

Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

HIGH 7.5EPSS 0.73%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
moxa/nport ia5150a firmware · moxa/nport ia5250a firmware · moxa/nport ia5450a firmware
Source
vulnerability@kaspersky.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.