← Back

CVE-2024-8455

nvd nist
Published: Sep 30, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.

Affected (3)

3 products
Gs 4210 24p2s Firmware
Gs 4210 24pl4c Firmware
Igs 5225 4up1t2s Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.305b240802
Running on/withPlatform Versions
Planet
Gs 4210 24p2s
Version 3.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.305b240719
Running on/withPlatform Versions
Planet
Gs 4210 24pl4c
Version 2.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Planet
Igs 5225 4up1t2s
Version 1.0

References (2)

Source: twcert@cert.org.tw
Third Party Advisory
Source: twcert@cert.org.tw
Third Party Advisory

Timeline

No history available yet.