cbcvebase.
CVE-2024-8458
published 2024-09-30

CVE-2024-8458: Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker…

PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.27%
18.2th percentile
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating accounts.

Affected

4 ranges
VendorProductVersion rangeFixed in
planetgs-4210-24p2s_firmware< 3.305b2408023.305b240802
planetgs-4210-24pl4c_firmware< 2.305b2407192.305b240719
planet_technologygs-4210-24p2s_hardware_3.0< 3.305b2408023.305b240802
planet_technologygs-4210-24pl4c_hardware_2.0< 2.305b2407192.305b240719
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.