VYPR
Unrated severityNVD Advisory· Published Apr 1, 2022· Updated Apr 16, 2025

Moxa NPort IAW5000A-I/O Series Serial Device Server Improper Input Validation

CVE-2021-32970

Description

Improper input validation in the built-in web server of Moxa NPort IAW5000A-I/O series firmware 2.2 or earlier allows data copy without validation, leading to denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper input validation in the built-in web server of Moxa NPort IAW5000A-I/O series firmware 2.2 or earlier allows data copy without validation, leading to denial of service.

Vulnerability

CVE-2021-32970 is an improper input validation vulnerability (CWE-20) in the built-in web server of Moxa NPort IAW5000A-I/O series wireless device servers. The vulnerability affects firmware version 2.2 or earlier [1][2]. Data can be copied without proper validation, which a remote attacker can exploit to cause denial-of-service conditions.

Exploitation

The attacker does not require authentication or user interaction; the vulnerability can be exploited over the network with low complexity (CVSS v3 vector string AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) [2]. An attacker sends specially crafted data to the built-in web server, which fails to validate the input, leading to a condition that disrupts device availability.

Impact

Successful exploitation results in a denial-of-service condition, impacting the availability of the device. The CVSS base score is 7.5 (High severity). The vulnerability does not directly affect confidentiality or integrity [2].

Mitigation

Moxa has released a firmware update to address this vulnerability. Users are advised to update to the latest firmware version for the NPort IAW5000A-I/O series. As of the advisory date (May 27, 2021), the fix is available [1]. CISA recommends that users take defensive measures to minimize exploitation risk [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.