Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Westernmo
Westernmo edw 100
CPEs cpe:2.3:h:westernmo:edw_100:*:*:*:*:*:*:*:*
Vendors & Products Westernmo
Westernmo edw 100
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-13T15:59:17.702Z

Reserved: 2024-05-19T00:00:00.000Z

Link: CVE-2024-36080

cve-icon Vulnrichment

Updated: 2024-08-02T03:30:12.997Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-19T20:15:08.107

Modified: 2024-11-21T09:21:36.270

Link: CVE-2024-36080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.