PLANET Technology Switches Vulnerable to CSRF Attacks
CVE-2024-8458

8.8HIGH

What is CVE-2024-8458?

Certain models of network switches from PLANET Technology are exposed to a Cross-Site Request Forgery (CSRF) vulnerability in their web application interface. This flaw permits an unauthenticated remote attacker to deceive a user into visiting a malicious web page, effectively allowing the attacker to execute commands under the guise of the user. This could lead to unauthorized actions, such as the creation of user accounts or alteration of configurations, thereby compromising the security and integrity of the affected devices.

Affected Version(s)

GS-4210-24P2S hardware 3.0 0 < 3.305b240802

GS-4210-24PL4C hardware 2.0 0 < 2.305b240719

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.