Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-49190 | Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices. | 
Solution
Update firmware of GS-4210-24PL4C hardware 2.0 to version 2.305b240719 or later. Update firmware of GS-4210-24P2S hardware 3.0 to version 3.305b240802 or later.
Workaround
No workaround given by the vendor.
Fri, 04 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Planet
         Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware  | 
|
| CPEs | cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:* cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Planet
         Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware  | 
Mon, 30 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Planet Technology Corp
         Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0  | 
|
| CPEs | cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:* cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Planet Technology Corp
         Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0  | 
|
| Metrics | 
        
        ssvc
         
  | 
Mon, 30 Sep 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices. | |
| Title | PLANET Technology switch devices - Missing Authentication for multiple HTTP routes | |
| Weaknesses | CWE-306 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-30T16:51:08.872Z
Reserved: 2024-09-05T02:53:09.094Z
Link: CVE-2024-8456
Updated: 2024-09-30T16:51:03.538Z
Status : Analyzed
Published: 2024-09-30T08:15:04.797
Modified: 2024-10-04T14:45:39.920
Link: CVE-2024-8456
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD