CVE-2024-36081
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
19/05/2024
Last modified:
26/08/2024
Description
Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



