CVE-2024-8456

EUVD-2024-49190
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
planetgs-4210-24p2s_firmware
𝑥
< 3.305b240802
planetgs-4210-24pl4c_firmware
𝑥
< 2.305b240719
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
planet_technology_corpgs-4210-24pl4c_hardware_2.0
𝑥
< 2.305b240719
ADP
planet_technology_corpgs-4210-24pl4c_hardware_3.0
𝑥
< 3.305b240802
ADP