Hard-coded community string in SNMPv1 service allows unauthorized access
CVE-2024-8450
9.8CRITICAL
What is CVE-2024-8450?
Certain switch models from PLANET Technology contain a hard-coded community string in the SNMPv1 service, which may lead to unauthorized access. Attackers can exploit this flaw to gain read-write privileges on the SNMPv1 service, posing significant security risks. This vulnerability emphasizes the need for proper configuration and secure coding practices to mitigate potential attacks on critical network infrastructure.
Affected Version(s)
GS-4210-24P2S hardware 3.0 0 < 3.305b240802
GS-4210-24PL4C hardware 2.0 0 < 2.305b240719