MEDIUM · 4.8

CVE-2024-8457

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arb...

Vulnerability Description

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
PlanetGs-4210-24P2S Firmware< 3.305b240802
PlanetGs-4210-24P2S3.0
PlanetGs-4210-24Pl4C Firmware< 2.305b240719
PlanetGs-4210-24Pl4C2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-8457?

CVE-2024-8457 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arb...

How severe is CVE-2024-8457?

CVE-2024-8457 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-8457?

Check the references section above for vendor advisories and patch information. Affected products include: Planet Gs-4210-24P2S Firmware, Planet Gs-4210-24P2S, Planet Gs-4210-24Pl4C Firmware, Planet Gs-4210-24Pl4C.