CVE-2024-36081: Critical severity Westermo EDW-100 vulnerability
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36081?
CVE-2024-36081 has a high severity level due to the potential exposure of cleartext passwords in configuration files.
How do I fix CVE-2024-36081?
To fix CVE-2024-36081, ensure you update your Westermo EDW-100 device to a version released after May 3, 2024.
What are the risks associated with CVE-2024-36081?
The risks include unauthorized access to sensitive configuration data, leading to potential exploitation of network resources.
Who is affected by CVE-2024-36081?
CVE-2024-36081 affects users of the Westermo EDW-100 devices up to the version released on May 3, 2024.
Can CVE-2024-36081 be exploited remotely?
Yes, CVE-2024-36081 can be exploited by an unauthenticated user remotely, compromising the device's security.