CVE-2024-8455

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:planet:igs-5225-4up1t2s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:planet:igs-5225-4up1t2s:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-30 08:15

Updated : 2024-10-04 14:45


NVD link : CVE-2024-8455

Mitre link : CVE-2024-8455

CVE.ORG link : CVE-2024-8455


JSON object : View

Products Affected

planet

  • igs-5225-4up1t2s_firmware
  • gs-4210-24pl4c_firmware
  • igs-5225-4up1t2s
  • gs-4210-24p2s_firmware
  • gs-4210-24pl4c
  • gs-4210-24p2s
CWE
CWE-261

Weak Encoding for Password

CWE-326

Inadequate Encryption Strength