CVE-2024-34542: Advantech ADAM-5630 Weak Encoding for Password
Published Sep 27, 2024
·Updated
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
Affected Software
2 affected components
All of the following
Advantech Adam-5630 Firmware<2.5.2
Advantech ADAM-5630
Remediation
Information
Advantech recommends users upgrade their ADAM-5630 devices to version 2.5.2 https://www.advantech.com/zh-tw/support/details/firmware .
Event History
Sep 27, 2024
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34542?
CVE-2024-34542 is considered a high severity vulnerability due to the exposure of user credentials in plain text.
2
How do I fix CVE-2024-34542?
To fix CVE-2024-34542, update the Advantech ADAM-5630 firmware to the latest version beyond 2.5.2.
3
What kind of information is exposed in CVE-2024-34542?
CVE-2024-34542 exposes user credentials, including usernames and passwords, in plain text during the login process.
4
Who is affected by CVE-2024-34542?
CVE-2024-34542 affects users of the Advantech ADAM-5630 with versions of the firmware up to and including 2.5.2.
5
Is CVE-2024-34542 an authentication vulnerability?
Yes, CVE-2024-34542 is an authentication vulnerability due to the insecure transmission of credentials.