Westermo WeOS
cpe:2.3:o:westermo:weos:*:*:*:*:*:*:*
- >= 5.24.0, <= 5.24.4
A vulnerability exists in Westermo WeOS versions 5.24 through 5.24.4, allowing unauthorized access to sensitive information such as credentials through verbose system logging. This log data can be accessed by users authorized to read syslog files.
The vulnerability could lead to unauthorized access to sensitive information, including credentials, through system logs.
Westermo recommends limiting access to administration accounts, storing audit records on a separate syslog server with access controls and encryption, and enabling TLS for remote logs using strong cipher suites.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.