CVE-2024-8457: PLANET Technology switch devices - Stored cross-site scripting (XSS) in the User Management
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8457?
CVE-2024-8457 is considered a high severity vulnerability due to its potential for remote stored XSS attacks.
How do I fix CVE-2024-8457?
To fix CVE-2024-8457, ensure that your PLANET Technology switch firmware is updated to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2024-8457?
CVE-2024-8457 affects specific models of PLANET Technology switches running older firmware versions.
What type of attack does CVE-2024-8457 enable?
CVE-2024-8457 enables a Stored Cross-Site Scripting (XSS) attack due to improper parameter validation.
Who can exploit CVE-2024-8457?
CVE-2024-8457 can be exploited by remote authenticated users with administrator privileges.