Attackers Can Crash PLANET Technology's swctrl Service with DoS Vulnerability
CVE-2024-8454

7.5HIGH

What is CVE-2024-8454?

A vulnerability exists in the swctrl service utilized by PLANET Technology devices, particularly affecting certain switch models. This vulnerability allows unauthenticated remote attackers to send specially crafted packets to the service, which can lead to a denial-of-service condition, causing the service to crash. This situation represents a significant risk to the reliability and availability of the affected devices, emphasizing the need for immediate attention by users and administrators managing these switches.

Affected Version(s)

GS-4210-24P2S hardware 3.0 0 < 3.305b240802

GS-4210-24PL4C hardware 2.0 0 < 2.305b240719

IGS-5225-4UP1T2S hardware 1.0 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.