VYPR
Unrated severityNVD Advisory· Published Apr 1, 2022· Updated Apr 16, 2025

Moxa NPort IAW5000A-I/O Series Serial Device Server Classic Buffer Overflow

CVE-2021-32968

Description

Two buffer overflows in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Two buffer overflows in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

Vulnerability

Two buffer overflow vulnerabilities exist in the built-in web server of Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier [1], [2]. These are classified as classic buffer overflows (CWE-120) and can be triggered by remote attackers without authentication or user interaction [2].

Exploitation

An attacker can exploit these vulnerabilities remotely over the network by sending specially crafted requests to the built-in web server [2]. No authentication or special privileges are required, and the attack complexity is low, meaning the attacker does not need to win a race condition or manipulate specific timing [2].

Impact

Successful exploitation allows a remote attacker to cause a denial-of-service condition, crashing the affected device [1], [2]. The CVSS v3 base score for these specific vulnerabilities is 7.5 with a vector of (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high availability impact but no impact on confidentiality or integrity [2].

Mitigation

Moxa has not released a firmware update for the NPort IAW5000A-I/O Series that addresses these buffer overflow vulnerabilities as of the advisory date (May 27, 2021) [1]. Users are advised to apply defense-in-depth measures, such as restricting network access to the device and using firewalls or VPNs [1], [2]. The vulnerabilities are not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.