PT-2024-28393 · Aginode · Aginode Gigaswitch V5

·

CVE-2024-39219

·

Published

2024-12-04

·

Updated

2025-01-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aginode GigaSwitch V5 versions prior to 7.06G
Description The issue allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to previously patched vulnerabilities. This can be done by exploiting insecure permissions in the device.
Recommendations For Aginode GigaSwitch V5 versions prior to 7.06G, update to version 7.06G or later to resolve the issue. As a temporary workaround, consider restricting access to firmware upload functionality to minimize the risk of exploitation. Restrict access to the SCP command to prevent attackers from accessing sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-39219

Affected Products

Aginode Gigaswitch V5