PLANET Technology switch devices - SSH server DoS attack
Published Sep 30, 2024
7.5
HIGHCVSS 3.1
EPSS 0.55%
Description
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.
Affected products
-
- Version 0StatusaffectedConstraints<3.305b240802
- Version
-
- Version 0StatusaffectedConstraints<2.305b240719
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| PLANET Technology | GS-4210-24P2S hardware 3.0 | unaffected |
| ||||||
| PLANET Technology | GS-4210-24PL4C hardware 2.0 | unaffected |
|
Configuration 1
- < 3.305b240802
Running on/with
- 3.0
Configuration 2
- < 2.305b240719
Running on/with
- 2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update firmware of GS-4210-24PL4C hardware 2.0 to version 2.305b240719 or later. Update firmware of GS-4210-24P2S hardware 3.0 to version 3.305b240802 or later.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49185 Advisory
- https://www.twcert.org.tw/en/cp-139-8052-ac0ea-2.html third-party-advisoryThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-8051-5048e-1.html third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49185 | Advisory | |
| https://www.twcert.org.tw/en/cp-139-8052-ac0ea-2.html | third-party-advisoryThird Party Advisory | |
| https://www.twcert.org.tw/tw/cp-132-8051-5048e-1.html | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.