Hard-coded Credentials in Password Recovery Functionality Expose Network Devices to Unauthorized Access
CVE-2024-8449
6.8MEDIUM
What is CVE-2024-8449?
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.
Affected Version(s)
GS-4210-24P2S hardware 3.0 0 < 3.305b240802
GS-4210-24PL4C hardware 2.0 0 < 2.305b240719