### [CVE-2020-27150](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27150) ![](https://img.shields.io/static/v1?label=Product&message=NPort%20IA5000A%20Series&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Unprotected%20Storage%20of%20Credentials&color=brighgreen) ### Description In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set. ### POC #### Reference - https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities - https://www.moxa.com/en/support/product-support/security-advisory/nport-ia5000a-serial-device-servers-vulnerabilities #### Github No PoCs found on GitHub currently.