8.1

CVSS3.1

CVE-2024-8455 - PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwords

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can โ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 7:24 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 2:45 p.m.

5.3

CVSS3.1

CVE-2024-8454 - PLANET Technology switch devices - Swctrl service DoS attack

The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

๐Ÿ“… Published: Sept. 30, 2024, 7:18 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:11 p.m.

4.9

CVSS3.1

CVE-2024-8453 - PLANET Technology switch devices - Weak hash for users' passwords

Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.

๐Ÿ“… Published: Sept. 30, 2024, 7:12 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:10 p.m.

6.9

CVSS4.0

CVE-2024-9329 - Glassfish redirect to untrusted site

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal uโ€ฆ

๐Ÿ“… Published: Sept. 30, 2024, 7:11 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:54 a.m.

7.5

CVSS3.1

CVE-2024-8452 - PLANET Technology switch devices - Insecure hash functions used for SNMPv3 credentials

Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.

๐Ÿ“… Published: Sept. 30, 2024, 7:07 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:10 p.m.

7.5

CVSS3.1

CVE-2024-8451 - PLANET Technology switch devices - SSH server DoS attack

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.

๐Ÿ“… Published: Sept. 30, 2024, 6:56 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:09 p.m.

8.6

CVSS3.1

CVE-2024-8450 - PLANET Technology switch devices - Hard-coded SNMPv1 read-write community string

Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges.

๐Ÿ“… Published: Sept. 30, 2024, 6:50 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:08 p.m.

6.8

CVSS3.1

CVE-2024-8449 - PLANET Technology switch devices - Local users' passwords recovery through hard-coded credentials

Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password.

๐Ÿ“… Published: Sept. 30, 2024, 6:45 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:08 p.m.

8.8

CVSS3.1

CVE-2024-8448 - PLANET Technology switch devices - Remote privilege escalation using hard-coded credentials

Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell.

๐Ÿ“… Published: Sept. 30, 2024, 6:36 a.m. ๐Ÿ”„ Last Modified: Oct. 4, 2024, 3:07 p.m.

5.4

CVSS3.1

CVE-2024-8536 - Ultimate Blocks < 3.2.2 - Contributor+ Stored XSS

The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

๐Ÿ“… Published: Sept. 30, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2024, 6:16 p.m.
Total resulsts: 349182
Page 8437 of 34,919
ยซ previous page ยป next page
Filters