PatchSiren cyber security CVE debrief
CVE-2024-48871 Planet Technology CVE debrief
CVE-2024-48871 is a critical stack-based buffer overflow vulnerability in the Planet Technology Planet WGS-804HPT industrial switch, published by CISA on December 5, 2024. The vulnerability exists in the device's webserver, which fails to properly validate input size before copying data to the stack. An unauthenticated remote attacker can exploit this flaw by sending a malicious HTTP request, potentially achieving remote code execution. The affected version is v1.305b210531. Planet Technology has released firmware version 1.305b241111 or later to address this vulnerability. Organizations should prioritize patching given the critical CVSS 9.8 score and the unauthenticated network attack vector.
- Vendor
- Planet Technology
- Product
- Planet WGS-804HPT
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-05
- Original CVE updated
- 2024-12-05
- Advisory published
- 2024-12-05
- Advisory updated
- 2024-12-05
Who should care
Organizations operating Planet WGS-804HPT industrial switches in manufacturing, utility, transportation, or other industrial environments should prioritize remediation. Security teams responsible for OT/ICS network security, infrastructure administrators managing industrial Ethernet switches, and compliance officers tracking critical vulnerability exposure should address this issue promptly.
Technical summary
The Planet WGS-804HPT webserver contains a stack-based buffer overflow vulnerability due to insufficient input size validation. When processing HTTP requests, the webserver copies data to the stack without proper bounds checking. An unauthenticated attacker can send a crafted HTTP request with oversized input to trigger the overflow, potentially overwriting return addresses and achieving arbitrary code execution. The vulnerability is remotely exploitable without authentication, making it particularly severe for internet-exposed or network-accessible devices.
Defensive priority
critical
Recommended defensive actions
- Upgrade Planet WGS-804HPT firmware to version 1.305b241111 or later as recommended by the vendor
- Restrict network access to the device's web management interface to trusted administrative hosts only
- Monitor for unauthorized HTTP requests to the device's webserver
- Apply network segmentation to isolate affected industrial switches from untrusted networks
- Review CISA's ICS recommended practices for defense-in-depth strategies
Evidence notes
The vulnerability description and remediation guidance are sourced from CISA's CSAF-formatted advisory. The affected product version and patch version are explicitly documented in the CSAF product tree. CVSS 3.1 vector confirms network attack vector with low attack complexity and no privileges required.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-48871 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-48871
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-48871 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-48871
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-340-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-340-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.