Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Planet
Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware |
|
CPEs | cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:* cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Planet
Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware |
Mon, 30 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 30 Sep 2024 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially. | |
Title | PLANET Technology switch devices - Insecure hash functions used for SNMPv3 credentials | |
Weaknesses | CWE-327 CWE-328 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-09-30T07:07:26.325Z
Updated: 2024-09-30T17:32:24.359Z
Reserved: 2024-09-05T02:53:04.816Z
Link: CVE-2024-8452
Vulnrichment
Updated: 2024-09-30T17:32:10.376Z
NVD
Status : Analyzed
Published: 2024-09-30T07:15:04.647
Modified: 2024-10-04T15:10:17.087
Link: CVE-2024-8452
Redhat
No data.