CVE Vulnerabilities

CVE-2024-8459

Cleartext Storage of Sensitive Information

Published: Sep 30, 2024 | Modified: Oct 04, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Certain switch models from PLANET Technology store SNMPv3 users passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Gs-4210-24p2s_firmwarePlanet*3.305b240802 (excluding)

Potential Mitigations

References