Multiple product vulnerabilities were identified in Moxa’s NPort IAW5000A-I/O Series Wireless Device Server. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Buffer Overflow (CWE-120) BDU:2021-02699, BDU:2021-02702 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack. |
| 2 | Stack-Based Buffer Overflow (CWE-121) BDU:2021-02700, BDU:2021-02701, BDU:2021-02703, BDU:2021-02704, BDU:2021-02708 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE). |
| 3 | Improper Input Validation (CWE-20) BDU:2021-02705, BDU:2021-02706 |
Data can be copied without validation in the built-in web server, which allows remote attackers to initiate a DoS attack. |
| 4 | OS Command Injection (CWE-78) BDU:2021-02707 |
Improper input validation in the built-in web server allows remote attackers to execute the OS command. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/nport-iaw5000a-io-serial-device-server-vulnerabilities