CVE-2024-8451

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*

History

04 Oct 2024, 15:09

Type Values Removed Values Added
CPE cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*
cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*
cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-8052-ac0ea-2.html - () https://www.twcert.org.tw/en/cp-139-8052-ac0ea-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-8051-5048e-1.html - () https://www.twcert.org.tw/tw/cp-132-8051-5048e-1.html - Third Party Advisory
First Time Planet gs-4210-24pl4c
Planet
Planet gs-4210-24pl4c Firmware
Planet gs-4210-24p2s
Planet gs-4210-24p2s Firmware

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) Ciertos modelos de conmutadores de PLANET Technology tienen un servicio SSH que maneja incorrectamente solicitudes de conexión insuficientemente autenticadas, lo que permite que atacantes remotos no autorizados exploten esta debilidad para ocupar ranuras de conexión y evitar que usuarios legítimos accedan al servicio SSH.

30 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 07:15

Updated : 2024-10-04 15:09


NVD link : CVE-2024-8451

Mitre link : CVE-2024-8451

CVE.ORG link : CVE-2024-8451


JSON object : View

Products Affected

planet

  • gs-4210-24p2s
  • gs-4210-24p2s_firmware
  • gs-4210-24pl4c_firmware
  • gs-4210-24pl4c
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges

CWE-400

Uncontrolled Resource Consumption