CVE-2024-8451

HIGH

PLANET Technology - Privilege Escalation

Title source: llm
STIX 2.1

Description

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.

Scores

CVSS v3 7.5
EPSS 0.0086
EPSS Percentile 75.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-280 CWE-400
Status published
Products (2)
planet/gs-4210-24p2s_firmware < 3.305b240802
planet/gs-4210-24pl4c_firmware < 2.305b240719
Published Sep 30, 2024
Tracked Since Feb 18, 2026