Moxa NPort IAW5000A-I/O Series Serial Device Server Improper Input Validation
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.7%
exploitation probability
1.7%top 26% of all CVEs
observed exploitation
nono source reports it
In short
The Moxa NPort IAW5000A-I/O serial device server's web interface does not properly validate incoming data, allowing remote attackers to send malicious requests that crash or disable the device.
Technical detail
The built-in web server in firmware 2.2 and earlier fails to validate user-supplied input before processing, enabling a remote unauthenticated attacker to trigger a denial-of-service condition through crafted network requests without requiring prior access or special configuration.
Summary generated and translated by AI from the official description.
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Moxa · NPort IAW5000A-I/O series firmware