ZeroHour

CVE-2024-8455

CVSS 3.1
5.9 medium
EPSS
<1%p27
Published
()
Modified
Description

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.

Vendors
planet
Products
gs-4210-24p2s firmware, gs-4210-24pl4c firmware, igs-5225-4up1t2s firmware
Weakness
CWE-261, CWE-326
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.