VulnerabilityAnalyzed
CVE-2024-8459
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
MEDIUM 4.9EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- planet/gs-4210-24p2s firmware · planet/gs-4210-24pl4c firmware
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/en/cp-139-8068-8aaa5-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-8067-2fc50-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.