Loading HuntDB...

Westermo

6 Products 17 CVEs

CVE Severity Distribution (All Time)

Critical
4
High
6
Medium
7
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-36081 CRITICAL None

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: thi…

CVE-2024-32943 HIGH 1 year ago

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

CVE-2024-35246 HIGH 1 year ago

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

CVE-2024-37183 MEDIUM 1 year ago

Plain text credentials and session ID can be captured with a network sniffer.

CVE-2023-40143 MEDIUM 1 year, 5 months ago

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cr…

CVE-2023-45735 HIGH 1 year, 5 months ago

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of …

CVE-2023-45222 MEDIUM 1 year, 5 months ago

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scr…

CVE-2023-45213 MEDIUM 1 year, 5 months ago

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning…

CVE-2023-42765 MEDIUM 1 year, 5 months ago

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the…

CVE-2023-40544 MEDIUM 1 year, 5 months ago

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitiv…