The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Planet
Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware Planet igs-5225-4up1t2s Planet igs-5225-4up1t2s Firmware |
|
Weaknesses | CWE-326 | |
CPEs | cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:* cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:* cpe:2.3:h:planet:igs-5225-4up1t2s:1.0:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:planet:igs-5225-4up1t2s_firmware:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Planet
Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware Planet igs-5225-4up1t2s Planet igs-5225-4up1t2s Firmware |
Mon, 30 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0 Planet Technology Corp igs-5225-4up1t2s Hardware 1.0 |
|
CPEs | cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:* cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:* cpe:2.3:a:planet_technology_corp:igs-5225-4up1t2s_hardware_1.0:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0 Planet Technology Corp igs-5225-4up1t2s Hardware 1.0 |
|
Metrics |
ssvc
|
Mon, 30 Sep 2024 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords. | |
Title | PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords | |
Weaknesses | CWE-261 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-09-30T07:24:49.379Z
Updated: 2024-09-30T16:54:36.168Z
Reserved: 2024-09-05T02:53:08.080Z
Link: CVE-2024-8455
Vulnrichment
Updated: 2024-09-30T16:54:29.090Z
NVD
Status : Analyzed
Published: 2024-09-30T08:15:04.570
Modified: 2024-10-04T14:45:48.727
Link: CVE-2024-8455
Redhat
No data.