CVE-2024-8458: PLANET Technology switch devices - Cross-site Request Forgery
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating accounts.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8458?
CVE-2024-8458 is classified as a medium severity vulnerability due to its potential for unauthorized actions via Cross-Site Request Forgery.
How do I fix CVE-2024-8458?
To fix CVE-2024-8458, users should update their firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-8458?
CVE-2024-8458 affects certain models of PLANET Technology switches with specific firmware versions.
What type of attack is CVE-2024-8458 associated with?
CVE-2024-8458 is associated with Cross-Site Request Forgery (CSRF) attacks that allow unauthorized actions to be executed.
Can CVE-2024-8458 be exploited remotely?
Yes, CVE-2024-8458 can be exploited remotely by an unauthenticated attacker through tricking a user into visiting a malicious website.