Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
History

Fri, 04 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Fri, 04 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware
CPEs cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
Vendors & Products Planet
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware
Planet gs-4210-24pl4c
Planet gs-4210-24pl4c Firmware
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Mon, 30 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0
Planet Technology Corp gs-4210-24pl4c Hardware 3.0
CPEs cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:*
cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:*
Vendors & Products Planet Technology Corp
Planet Technology Corp gs-4210-24pl4c Hardware 2.0
Planet Technology Corp gs-4210-24pl4c Hardware 3.0
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 08:15:00 +0000

Type Values Removed Values Added
Description Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
Title PLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwords
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-09-30T07:59:27.614Z

Updated: 2024-09-30T16:13:57.982Z

Reserved: 2024-09-05T02:53:12.647Z

Link: CVE-2024-8459

cve-icon Vulnrichment

Updated: 2024-09-30T16:13:48.359Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T08:15:05.460

Modified: 2024-10-04T14:42:35.297

Link: CVE-2024-8459

cve-icon Redhat

No data.