CVE-2024-8456
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, a
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.
CRITICAL · CVSS 9.8
EPSS 0.01594
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0