Security Advisory

CVE-2024-8455

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-09-30 07:24:49
Last updated 2024-09-30 16:54:36
Assigner twcert
State PUBLISHED

Description

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them to obtain plaintext passwords.