Moxa NPort IAW5000A-I/O Series Serial Device Server Classic Buffer Overflow
Description
Two buffer overflows in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Two buffer overflows in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.
Vulnerability
Two buffer overflow vulnerabilities exist in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier [1], [2]. These are classified as classic buffer overflows (CWE-120) and can be triggered by remote attackers without authentication or user interaction [2].
Exploitation
An attacker can exploit these vulnerabilities remotely over the network by sending specially crafted requests to the built-in web server [2]. No authentication or special privileges are required, and the attack complexity is low, meaning the attacker does not need to win a race condition or manipulate specific timing [2].
Impact
Successful exploitation allows a remote attacker to cause a denial-of-service condition, crashing the affected device [1], [2]. The CVSS v3 base score for these specific vulnerabilities is 7.5 with a vector of (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high availability impact but no impact on confidentiality or integrity [2].
Mitigation
Moxa has not released a firmware update for the NPort IAW5000A-I/O Series that addresses these buffer overflow vulnerabilities as of the advisory date (May 27, 2021) [1]. Users are advised to apply defense-in-depth measures, such as restricting network access to the device and using firewalls or VPNs [1], [2]. The vulnerabilities are not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= 2.2
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.cisa.gov/uscert/ics/advisories/icsa-21-187-01mitrex_refsource_CONFIRM
- www.moxa.com/en/support/product-support/security-advisory/nport-iaw5000a-io-serial-device-server-vulnerabilitiesmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.