PT-2024-10297 · Planet Technology · Planet Switches

Tomer Goldschmidt

·

Published

2024-11-15

·

Updated

2025-01-22

·

CVE-2024-52320

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Planet Switches (affected versions not specified)
Description The issue exists due to the lack of measures to neutralize special elements in the firmware of PLANET Technology switches. An unauthenticated attacker could send commands through a malicious HTTP request, potentially resulting in remote code execution. This can be achieved by exploiting a command injection vulnerability, allowing attackers to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00722
CVE-2024-52320

Affected Products

Planet Switches