Planet WGS-804HPT Industrial Switch flaws could be chained to achieve remote code execution
ID: d0bf7ed7-5518-5b60-93ec-40d8d0534f44
STIX ID: report--d0bf7ed7-5518-5b60-93ec-40d8d0534f44
Feed Name: Security Affairs
Threat Score
Claroty disclosed three vulnerabilities in Planet WGS-804HPT industrial switches — CVE-2024-48871 (stack-based buffer overflow, CVSS 9.8), CVE-2024-52320 (OS command injection, CVSS 9.8), and CVE-2024-52558 (integer underflow, CVSS 5.3) — which can be chained to achieve unauthenticated remote code execution and potential lateral movement; Planet released firmware v1.305b241111 to mitigate the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
