Impact
The firmware versions of PLANET IGS‑5225‑8P2T4S switches before 1.2412b260707 for V1 and 2.2412b260519 for V2 use MD5 to hash privileged‑mode passwords. MD5 is a broken hash algorithm that can be inverted with preimage attacks, enabling a malicious actor who obtains the configuration file to recover the password. This leads to exposure of privileged credentials and potential control over the switch.
Affected Systems
PLANET Technology Corp. PLANET IGS‑5225‑8P2T4S switches with V1 firmware earlier than 1.2412b260707 or V2 firmware earlier than 2.2412b260519 are affected. These industrial switches are often deployed in operational technology environments where configuration files may be accessed through physical media or remote management interfaces.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity, and the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred: an attacker must obtain the device’s configuration file, which can occur through physical access, a compromised management session, or a fault in configuration management. If such access is achieved, the attacker can recover the privileged‑mode password and gain unauthorized control of the switch.
OpenCVE Enrichment