CVE-2024-8449
PLANET Technology switch devices - Local users' passwords recovery through hard-coded credentials
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
PLANET Technology · GS-4210-24P2S hardware 3.0PLANET Technology · GS-4210-24PL4C hardware 2.0Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →