PT-2024-28393 · Aginode · Aginode Gigaswitch V5

Christophe Hugueny

+1

·

Published

2024-12-04

·

Updated

2025-01-15

·

CVE-2024-39219

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aginode GigaSwitch V5 versions prior to 7.06G
Description The issue allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to previously patched vulnerabilities. This can be done by exploiting insecure permissions in the device.
Recommendations For Aginode GigaSwitch V5 versions prior to 7.06G, update to version 7.06G or later to resolve the issue. As a temporary workaround, consider restricting access to firmware upload functionality to minimize the risk of exploitation. Restrict access to the SCP command to prevent attackers from accessing sensitive information.

Fix

Related Identifiers

CVE-2024-39219

Affected Products

Aginode Gigaswitch V5