Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 04 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Planet Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware | |
| CPEs | cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:* cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Planet Planet gs-4210-24p2s Planet gs-4210-24p2s Firmware Planet gs-4210-24pl4c Planet gs-4210-24pl4c Firmware | 
Mon, 30 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Planet Technology Corp Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0 | |
| CPEs | cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:* cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:* | |
| Vendors & Products | Planet Technology Corp Planet Technology Corp gs-4210-24pl4c Hardware 2.0 Planet Technology Corp gs-4210-24pl4c Hardware 3.0 | |
| Metrics | ssvc 
 | 
Mon, 30 Sep 2024 07:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password. | |
| Title | PLANET Technology switch devices - Local users' passwords recovery through hard-coded credentials | |
| Weaknesses | CWE-798 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: twcert
Published: 2024-09-30T06:45:27.302Z
Updated: 2024-09-30T17:05:21.197Z
Reserved: 2024-09-05T02:53:01.149Z
Link: CVE-2024-8449
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-09-30T17:05:14.943Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-09-30T07:15:03.937
Modified: 2024-10-04T15:08:22.733
Link: CVE-2024-8449
 Redhat
                        Redhat
                    No data.