|
252761
|
7.5 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 …
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2024-8452
|
2024-10-5 00:10 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252762
|
7.5 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakn…
|
CWE-400 CWE-280
Uncontrolled Resource Consumption Improper Handling of Insufficient Permissions or Privileges
|
CVE-2024-8451
|
2024-10-5 00:09 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252763
|
9.8 |
CRITICAL
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8450
|
2024-10-5 00:08 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252764
|
6.8 |
MEDIUM
Physics
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial consol…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8449
|
2024-10-5 00:08 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252765
|
8.8 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-8448
|
2024-10-5 00:07 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252766
|
4.8 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8457
|
2024-10-4 23:45 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252767
|
9.8 |
CRITICAL
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and sy…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8456
|
2024-10-4 23:45 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252768
|
5.9 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware igs-5225-4up1t2s_firmware
|
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user p…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2024-8455
|
2024-10-4 23:45 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252769
|
4.9 |
MEDIUM
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and ob…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-8459
|
2024-10-4 23:42 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252770
|
8.8 |
HIGH
Network
|
planet
|
gs-4210-24p2s_firmware gs-4210-24pl4c_firmware
|
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malici…
|
CWE-352
Origin Validation Error
|
CVE-2024-8458
|
2024-10-4 23:42 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|