CVE Vulnerabilities

CVE-2024-36081

Plaintext Storage of a Password

Published: May 19, 2024 | Modified: Aug 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

Weakness

Storing a password in plaintext may result in a system compromise.

Potential Mitigations

References