PT-2026-83272 · Planet · Gs-4210-16P2S V3
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PLANET GS-4210-16P2S V3 versions prior to 3.441b260626
Description
Multiple authenticated stack buffer overflow issues exist in the
/cgi-bin/dispatcher.cgi endpoint. The vulnerability occurs when several handlers copy attacker-controlled POST parameters into fixed-size stack buffers without proper length validation. Affected handlers include web vlan membership edit dialog post, web dai vlan post, web poe alive rmtip post, web sys sntp post, web tool upgradeManager post, web port countersClr post, web rmon statisticsClr post, web cablediag copper post, web aaa *Authlist*, web acl mgmt Rules Apply post, web acl mgmt Rules Edit post, web acl *AceDel post, web acl *AceAdd/Edit post, web acl bindAdd post, web acl bindEdit post, web snmp v3view add post, web snmp v3group add post, web snmp v3community add post, web snmp v3host add post, web snmp notifyv3 add post, web snmp v3user add post, web snmpv3 remote engineId add post, web stp globalSetting post, web isg db post, web tacplus* post, web dhcp option82 post, and web dhcp port option82 cid post. A remote authenticated attacker can send crafted requests to crash the CGI process or web management service, leading to a denial of service.Recommendations
Update to version 3.441b260626 or later.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gs-4210-16P2S V3