Description
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.
Published: 2024-09-30
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update firmware of GS-4210-24PL4C hardware 2.0 to version 2.305b240719 or later. Update firmware of GS-4210-24P2S hardware 3.0 to version 3.305b240802 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-49187 Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.
History

Fri, 04 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware
CPEs cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
Vendors & Products Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware

Mon, 30 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 07:30:00 +0000

Type Values Removed Values Added
Description Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.
Title PLANET Technology switch devices - Weak hash for users' passwords
Weaknesses CWE-328
CWE-759
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Planet Gs-4210-24p2s Gs-4210-24p2s Firmware Gs-4210-24pl4c Gs-4210-24pl4c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-30T15:47:03.144Z

Reserved: 2024-09-05T02:53:06.043Z

Link: CVE-2024-8453

cve-icon Vulnrichment

Updated: 2024-09-30T15:46:56.955Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T08:15:04.093

Modified: 2024-10-04T15:10:54.507

Link: CVE-2024-8453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses