The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.
History

Fri, 04 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware
Planet igs-5225-4up1t2s
Planet igs-5225-4up1t2s Firmware
Weaknesses CWE-326
CPEs cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:igs-5225-4up1t2s:1.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:planet:igs-5225-4up1t2s_firmware:-:*:*:*:*:*:*:*
Vendors & Products Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware
Planet igs-5225-4up1t2s
Planet igs-5225-4up1t2s Firmware

Mon, 30 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0
Planet Technology Corp gs-4210-24pl4c Hardware 3.0
Planet Technology Corp igs-5225-4up1t2s Hardware 1.0
CPEs cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:*
cpe:2.3:a:planet_technology_corp:igs-5225-4up1t2s_hardware_1.0:*:*:*:*:*:*:*:*
Vendors & Products Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0
Planet Technology Corp gs-4210-24pl4c Hardware 3.0
Planet Technology Corp igs-5225-4up1t2s Hardware 1.0
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 07:30:00 +0000

Type Values Removed Values Added
Description The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.
Title PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords
Weaknesses CWE-261
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-30T07:24:49.379Z

Updated: 2024-09-30T16:54:36.168Z

Reserved: 2024-09-05T02:53:08.080Z

Link: CVE-2024-8455

cve-icon Vulnrichment

Updated: 2024-09-30T16:54:29.090Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T08:15:04.570

Modified: 2024-10-04T14:45:48.727

Link: CVE-2024-8455

cve-icon Redhat

No data.