CVE-2024-36080: Critical severity Westermo EDW-100 vulnerability
Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36080?
CVE-2024-36080 is considered a high-severity vulnerability due to the presence of a hidden root user account with a hardcoded password.
How do I fix CVE-2024-36080?
There are no available fixes for CVE-2024-36080; users should avoid placing the affected Westermo EDW-100 devices at the edge of the network.
What are the potential risks associated with CVE-2024-36080?
The hidden root account with a hardcoded password can lead to unauthorized access, making the devices vulnerable to attacks.
Which devices are affected by CVE-2024-36080?
CVE-2024-36080 affects Westermo EDW-100 devices running firmware up to and including version 2024-05-03.
Is it safe to use Westermo EDW-100 devices given CVE-2024-36080?
It is not recommended to use Westermo EDW-100 devices at the network edge due to the significant risk posed by CVE-2024-36080.