7.5
CVE-2020-7003
- EPSS 0.2%
- Veröffentlicht 24.03.2020 18:15:18
- Zuletzt bearbeitet 21.11.2024 05:36:28
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Iologik 2512 Firmware Version <= 3.0
Moxa ≫ Iologik 2512-t Firmware Version <= 3.0
Moxa ≫ Iologik 2512-hspa Firmware Version <= 3.0
Moxa ≫ Iologik 2512-hspa-t Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-eu Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-eu-t Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-us Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-us-t Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-jp Firmware Version <= 3.0
Moxa ≫ Iologik 2512-wl1-jp-t Firmware Version <= 3.0
Moxa ≫ Iologik 2542 Firmware Version <= 3.0
Moxa ≫ Iologik 2542-t Firmware Version <= 3.0
Moxa ≫ Iologik 2542-hspa Firmware Version <= 3.0
Moxa ≫ Iologik 2542-hspa-t Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-eu Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-eu-t Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-us Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-us-t Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-jp Firmware Version <= 3.0
Moxa ≫ Iologik 2542-wl1-jp-t Firmware Version <= 3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.