{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-29T14:52:43.374","vulnerabilities":[{"cve":{"id":"CVE-2024-8448","sourceIdentifier":"twcert@cert.org.tw","published":"2024-09-30T07:15:03.507","lastModified":"2026-06-17T08:22:35.627","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell."},{"lang":"es","value":"Ciertos modelos de conmutadores de PLANET Technology tienen una credencial codificada en la interfaz de línea de comandos específica, lo que permite a atacantes remotos con privilegios regulares iniciar sesión con esta credencial y obtener un shell raíz de Linux."}],"affected":[{"source":"twcert@cert.org.tw","affectedData":[{"vendor":"PLANET Technology","product":"GS-4210-24PL4C hardware 2.0","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.305b240719","versionType":"custom","status":"affected"}]},{"vendor":"PLANET Technology","product":"GS-4210-24P2S hardware 3.0","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.305b240802","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"planet_technology_corp","product":"gs-4210-24pl4c_hardware_2.0","defaultStatus":"unknown","cpes":["cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_2.0:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"2.305b240719","versionType":"custom","status":"affected"}]},{"vendor":"planet_technology_corp","product":"gs-4210-24pl4c_hardware_3.0","defaultStatus":"unknown","cpes":["cpe:2.3:a:planet_technology_corp:gs-4210-24pl4c_hardware_3.0:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"3.305b240802","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"twcert@cert.org.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-30T17:05:49.040891Z","id":"CVE-2024-8448","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"twcert@cert.org.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:planet:gs-4210-24p2s_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"3.305b240802","matchCriteriaId":"89C0B4AA-848F-4AAC-8C51-8C10AEF0630A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:planet:gs-4210-24p2s:3.0:*:*:*:*:*:*:*","matchCriteriaId":"2A30964B-E6B8-4B8A-BE2E-882C0F3D8298"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:planet:gs-4210-24pl4c_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.305b240719","matchCriteriaId":"0E17E272-4418-4CE7-8E59-44953D19D659"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:planet:gs-4210-24pl4c:2.0:*:*:*:*:*:*:*","matchCriteriaId":"F8029517-8FAB-4130-81F3-98BB09F4814E"}]}]}],"references":[{"url":"https://www.twcert.org.tw/en/cp-139-8046-057c2-2.html","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]},{"url":"https://www.twcert.org.tw/tw/cp-132-8045-a2804-1.html","source":"twcert@cert.org.tw","tags":["Third Party Advisory"]}]}}]}