Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36487 | Plain text credentials and session ID can be captured with a network sniffer. |
Solution
No solution given by the vendor.
Workaround
Westermo advises users to disable HTTP access to the WebGUI and instead use HTTPS instead. This change will secure the credentials and session IDs, effectively nullifying the exploits described. To mitigate the risk of a denial-of-service attack through continuous login attempts, Westermo recommends disabling access to the device's WebGUI on external communication interfaces. For devices in production environments, disabling the WebGUI is suggested if possible. Westermo suggests limiting access to the device's CLI on external communication interfaces to prevent SSH DOS attacks through repeated login attempts. Westermo will keep users updated on any further enhancements.
Wed, 30 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Westermo
Westermo l210-f2g Westermo l210-f2g Firmware |
|
| CPEs | cpe:2.3:h:westermo:l210-f2g:-:*:*:*:*:*:*:* cpe:2.3:o:westermo:l210-f2g_firmware:4.21.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Westermo
Westermo l210-f2g Westermo l210-f2g Firmware |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-02T03:50:55.374Z
Reserved: 2024-06-13T14:52:17.253Z
Link: CVE-2024-37183
Updated: 2024-08-02T03:50:55.374Z
Status : Analyzed
Published: 2024-06-20T22:15:15.580
Modified: 2025-07-30T18:09:28.630
Link: CVE-2024-37183
No data.
OpenCVE Enrichment
No data.
EUVD