GPU VulnDB

Database/Control plane, storage & DevOps

Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remote

CVE-2021-32974Control plane, storage & DevOpsICSA-21-187-01curated

Impact

The built-in web server doesn't validate input properly, letting a remote unauthenticated attacker run arbitrary commands on the device server — full takeover of the box bridging serial equipment onto the network.

Who can reach it

Remote, unauthenticated — a crafted HTTP request to the web management interface is enough.

What to do

Firmware upgrade to the version Moxa published in its security advisory; requires a flash and reboot on every affected unit, which briefly drops the serial sessions it's carrying. No compensating config change exists since the flaw is in input handling, not a feature you can disable.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.