CVE-2024-8449: Planet Gs-4210-24p2s Firmware
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.
Affected products
- Planet Gs-4210-24p2s Firmware: before 3.305b240802 (fixed in 3.305b240802)
- Planet Gs-4210-24pl4c Firmware: before 2.305b240719 (fixed in 2.305b240719)
Published 2024-09-30. Last modified 2026-06-17.