CVE-2024-8453

MEDIUM

PLANET Technology - Info Disclosure

Title source: llm
STIX 2.1

Description

Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8055-2c361-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8056-09688-2.html

Scores

CVSS v3 4.9
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-328 CWE-759
Status published
Products (2)
planet/gs-4210-24p2s_firmware < 3.305b240802
planet/gs-4210-24pl4c_firmware < 2.305b240719
Published Sep 30, 2024
Tracked Since Feb 18, 2026