CVE-2024-36081

Severity CVSS v4.0:
Pending analysis
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
19/05/2024
Last modified:
26/08/2024

Description

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.