CVE-2020-25194
HIGH WAF: Low
CVSS 8.8
Published: 2020-12-23
CWE-269 CWE-269
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.
WAF Coverage Analysis
Improper Privilege Management
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Improper Privilege Management
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| moxa | nport_iaw5000a-i\/o_firmware | up to 2.1 |
References
- us-cert.cisa.gov (Third Party Advisory, US Government Resource)