CVE Vulnerabilities

CVE-2024-8455

Weak Encoding for Password

Published: Sep 30, 2024 | Modified: Oct 04, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.

Weakness

Obscuring a password with a trivial encoding does not protect the password.

Affected Software

Name Vendor Start Version End Version
Gs-4210-24p2s_firmware Planet * 3.305b240802 (excluding)

Potential Mitigations

References