CVE-2024-8452
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.
Affected (2)
Products: Planet: Gs 4210 24p2s Firmware, Gs 4210 24pl4c Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.305b240802 |
| Running on/with | Platform Versions |
|---|---|
Planet Gs 4210 24p2s | Version 3.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.305b240719 |
| Running on/with | Platform Versions |
|---|---|
Planet Gs 4210 24pl4c | Version 2.0 |
Related CWEs
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CWE-328
Use of Weak Hash
The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
References (2)
Timeline
No history available yet.