cbcvebase.
CVE-2024-8449
published 2024-09-30

CVE-2024-8449: Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to…

PriorityP433medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.26%
17.3th percentile
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

Affected

4 ranges
VendorProductVersion rangeFixed in
planetgs-4210-24p2s_firmware< 3.305b2408023.305b240802
planetgs-4210-24pl4c_firmware< 2.305b2407192.305b240719
planet_technologygs-4210-24p2s_hardware_3.0< 3.305b2408023.305b240802
planet_technologygs-4210-24pl4c_hardware_2.0< 2.305b2407192.305b240719
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.