Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 26 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-256
CWE-522

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-13T15:59:18.236Z

Reserved: 2024-05-19T00:00:00.000Z

Link: CVE-2024-36081

cve-icon Vulnrichment

Updated: 2024-08-02T03:30:12.820Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-19T20:15:08.287

Modified: 2024-11-21T09:21:36.423

Link: CVE-2024-36081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.