CVE-2025-15017 (CNNVD-202512-5670)
中文标题:
Moxa NPort 5000 Series 安全漏洞
英文标题:
A vulnerability exists in serial device servers where active debug code remains enabled in the UART ...
漏洞描述
中文描述:
Moxa NPort 5000 Series是中国台湾Moxa公司的一系列工业级串口联网服务器。 Moxa NPort 5000 Series存在安全漏洞,该漏洞源于UART接口中调试代码未禁用,可能导致未经授权的访问。
英文描述:
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access to internal debug functionality. Exploitation is low complexity and allows an attacker to execute privileged operations and access sensitive system resources, resulting in a high impact to the confidentiality, integrity, and availability of the affected device. No security impact to external or dependent systems has been identified.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Moxa | NPort 5000AI-M12 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5000ai-m12_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5100 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5100_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5100A Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5100a_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5200 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5200_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5200A Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5200a_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5400 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5400_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5600 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5600_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort 5600-DT Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_5600-dt_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort IA5000 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_ia5000_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort IA5000A Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_ia5000a_series:1.0:*:*:*:*:*:*:*
|
| Moxa | NPort IA5000-G2 Series | 1.0 | - | - |
cpe:2.3:a:moxa:nport_ia5000-g2_series:1.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-15017 |
2026-01-01 04:27:14 | 2026-01-12 02:11:12 |
| NVD | nvd_CVE-2025-15017 |
2026-01-01 04:27:49 | 2026-01-12 02:27:32 |
| CNNVD | cnnvd_CNNVD-202512-5670 |
2026-01-11 06:15:05 | 2026-01-12 02:38:11 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202512-5670
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']