CVE-2024-8449

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/09/2024
Last modified:
04/10/2024

Description

Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:* 3.305b240802 (excluding)
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:* 2.305b240719 (excluding)
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*