cbcvebase.
CVE-2024-8457
published 2024-09-30

CVE-2024-8457: Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users…

PriorityP421medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.28%
20.1th percentile
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

Affected

4 ranges
VendorProductVersion rangeFixed in
planetgs-4210-24p2s_firmware< 3.305b2408023.305b240802
planetgs-4210-24pl4c_firmware< 2.305b2407192.305b240719
planet_technologygs-4210-24p2s_hardware_3.0< 3.305b2408023.305b240802
planet_technologygs-4210-24pl4c_hardware_2.0< 2.305b2407192.305b240719
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.