← volver
CVE-2024-8456criticalCWE-306

PLANET Technology switch devices - Missing Authentication for multiple HTTP routes

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 0.6%
probabilidad de explotación
0.6%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H