In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account
Published Feb 26, 2020
7.5
HIGHCVSS 3.1
EPSS 0.59%
Description
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.
Affected products
No data.
Configuration 1
- ≤ 3.0
Running on/with
- n/a
Configuration 2
- ≤ 3.0
Running on/with
- n/a
Configuration 3
- ≤ 3.0
Running on/with
- n/a
Configuration 4
- ≤ 3.0
Running on/with
- n/a
Configuration 5
- ≤ 3.0
Running on/with
- n/a
Configuration 6
- ≤ 3.0
Running on/with
- n/a
Configuration 7
- ≤ 3.0
Running on/with
- n/a
Configuration 8
- ≤ 3.0
Running on/with
- n/a
Configuration 9
- ≤ 3.0
Running on/with
- n/a
Configuration 10
- ≤ 3.0
Running on/with
- n/a
Configuration 11
- ≤ 3.0
Running on/with
- n/a
Configuration 12
- ≤ 3.0
Running on/with
- n/a
Configuration 13
- ≤ 3.0
Running on/with
- n/a
Configuration 14
- ≤ 3.0
Running on/with
- n/a
Configuration 15
- ≤ 3.0
Running on/with
- n/a
Configuration 16
- ≤ 3.0
Running on/with
- n/a
Configuration 17
- ≤ 3.0
Running on/with
- n/a
Configuration 18
- ≤ 3.0
Running on/with
- n/a
Configuration 19
- ≤ 3.0
Running on/with
- n/a
Configuration 20
- ≤ 3.0
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (1)
- https://www.us-cert.gov/ics/advisories/icsa-20-056-02 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-20-056-02 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.