CVE-2024-37187: Advantech ADAM-5550 Weak Encoding for Password
Published Sep 27, 2024
·Updated
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
Affected Software
2 affected components
All of the following
Advantech Adam-5550 Firmware
Advantech ADAM-5550
Remediation
Information
ADAM-5550 is currently being phased out, and Advantech strongly
recommends all ADAM-5550 users upgrade to ADAM-5630 firmware version
2.5.2 or higher.
Event History
Sep 27, 2024
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37187?
CVE-2024-37187 has a medium severity rating due to the exposure of user credentials with weak encryption.
2
How do I fix CVE-2024-37187?
To address CVE-2024-37187, update the Advantech ADAM-5550 firmware to the latest version that resolves the credential storage issue.
3
What are the risks associated with CVE-2024-37187?
The risks associated with CVE-2024-37187 include unauthorized access to the system due to weakly encrypted user credentials.
4
What systems are affected by CVE-2024-37187?
CVE-2024-37187 affects the Advantech ADAM-5550 and its firmware versions.
5
Is CVE-2024-37187 easy to exploit?
CVE-2024-37187 can be exploited relatively easily due to the use of base64 encoding for credential storage.