Back

CRITICAL

PLANET Technology switch devices - Hard-coded SNMPv1 read-write community string

Published Sep 30, 2024

Description

Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges.

Affected products

Remediation

Vendor solution

Update firmware of GS-4210-24PL4C hardware 2.0 to version 2.305b240719 or later. Update firmware of GS-4210-24P2S hardware 3.0 to version 3.305b240802 or later.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Sep 30, 2024
Updated Sep 30, 2024
Reserved Sep 5, 2024
CISA Vulnrichment
Updated Sep 30, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner twcert
Published Sep 30, 2024
Updated Sep 30, 2024
Exploited since n/a
EUVD-2024-49184