ZeroHour

CVE-2024-8449

CVSS 3.1
6.8 medium
EPSS
<1%p19
Published
()
Modified
Description

Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

Vendors
planet
Products
gs-4210-24p2s firmware, gs-4210-24pl4c firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.