CVE-2024-8458
EUVD-2024-4919230.09.2024, 08:15
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating accounts.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| planet | gs-4210-24p2s_firmware | 𝑥 < 3.305b240802 |
| planet | gs-4210-24pl4c_firmware | 𝑥 < 2.305b240719 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| planet_technology_corp | gs-4210-24pl4c_hardware_2.0 | 𝑥 < 2.305b240719 | ADP |
| planet_technology_corp | gs-4210-24pl4c_hardware_3.0 | 𝑥 < 3.305b240802 | ADP |
Common Weakness Enumeration