目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-8451— PLANET switch devices 安全漏洞

CVSS 7.5 · High EPSS 0.55% · P43
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-8451の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
PLANET Technology switch devices - SSH server DoS attack
ソース: NVD (National Vulnerability Database)
脆弱性説明
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
未加控制的资源消耗(资源穷尽)
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
PLANET switch devices 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
PLANET switch devices是中国PLANET公司的一系列交换器设备。 PLANET switch devices存在安全漏洞,该漏洞源于SSH服务对未充分认证的连接请求处理不当,允许未经授权的远程攻击者利用此弱点占用连接槽位并阻止合法用户访问SSH服务。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
PLANET TechnologyGS-4210-24PL4C hardware 2.0 0 ~ 2.305b240719 -
PLANET TechnologyGS-4210-24P2S hardware 3.0 0 ~ 3.305b240802 -

II. CVE-2024-8451の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-8451のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · PLANET Technology · 2024-09-30 · 12 CVEs total

CVE-2024-84569.8 CRITICALPLANET Technology switch devices - Missing Authentication for multiple HTTP routes
CVE-2024-84588.8 HIGHPLANET Technology switch devices - Cross-site Request Forgery
CVE-2024-84488.8 HIGHPLANET Technology switch devices - Remote privilege escalation using hard-coded credential
CVE-2024-84508.6 HIGHPLANET Technology switch devices - Hard-coded SNMPv1 read-write community string
CVE-2024-84558.1 HIGHPLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords
CVE-2024-84527.5 HIGHPLANET Technology switch devices - Insecure hash functions used for SNMPv3 credentials
CVE-2024-84597.2 HIGHPLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwords
CVE-2024-84496.8 MEDIUMPLANET Technology switch devices - Local users' passwords recovery through hard-coded cred
CVE-2024-84545.3 MEDIUMPLANET Technology switch devices - Swctrl service DoS attack
CVE-2024-84534.9 MEDIUMPLANET Technology switch devices - Weak hash for users' passwords
CVE-2024-84574.8 MEDIUMPLANET Technology switch devices - Stored cross-site scripting (XSS) in the User Managemen

IV. 関連脆弱性

V. CVE-2024-8451へのコメント

まだコメントはありません


コメントを残す