7.5
CVE-2024-8451
- EPSS 0.55%
- Veröffentlicht 30.09.2024 07:15:04
- Zuletzt bearbeitet 04.10.2024 15:09:42
- CVE-Watchlists
- Unerledigt
PLANET Technology switch devices - SSH server DoS attack
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Planet ≫ Gs-4210-24p2s Firmware Version < 3.305b240802
Planet ≫ Gs-4210-24pl4c Firmware Version < 2.305b240719
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.421 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| Cert TW | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-280 Improper Handling of Insufficient Permissions or Privileges
The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://www.twcert.org.tw/en/cp-139-8052-ac0ea-2.html
https://www.twcert.org.tw/tw/cp-132-8051-5048e-1.html