CVE-2024-8449
30.09.2024, 07:15
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.Enginsight
Vendor | Product | Version |
---|---|---|
planet | gs-4210-24p2s_firmware | 𝑥 < 3.305b240802 |
planet | gs-4210-24pl4c_firmware | 𝑥 < 2.305b240719 |
𝑥
= Vulnerable software versions