PT-2024-39028 · Planet Technology · Planet Technology Switch

Published

2024-09-30

·

Updated

2024-10-04

·

CVE-2024-8459

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PLANET Technology switch models (affected versions not specified)
Description: The issue concerns certain switch models from PLANET Technology that store SNMPv3 users' passwords in plaintext within the configuration files. This allows remote attackers with administrator privileges to read the file and obtain the credentials.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-8459

Affected Products

Planet Technology Switch