Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
https://www.twcert.org.tw/tw/cp-132-8067-2fc50-1.html
https://www.twcert.org.tw/en/cp-139-8068-8aaa5-2.html
https://securityonline.info/planet-technology-switches-face-cve-2024-8456-cvss-9-8-urgent-firmware-updates-advised/?&web_view=true
Source: Mitre, NVD
Published: 2024-09-30
Updated: 2024-10-04
Base Score: 6.1
Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N
Severity: Medium
Base Score: 4.9
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.00057