PatchSiren cyber security CVE debrief
CVE-2024-52320 Planet Technology CVE debrief
A critical command injection vulnerability in the Planet Technology Planet WGS-804HPT industrial switch allows unauthenticated remote attackers to execute arbitrary code via malicious HTTP requests. The vulnerability, published December 5, 2024, carries a CVSS 3.1 score of 9.8 (Critical) and affects firmware version 1.305b210531. Planet Technology has released patched firmware version 1.305b241111 to address this issue.
- Vendor
- Planet Technology
- Product
- Planet WGS-804HPT
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-05
- Original CVE updated
- 2024-12-05
- Advisory published
- 2024-12-05
- Advisory updated
- 2024-12-05
Who should care
Organizations operating Planet WGS-804HPT industrial switches in manufacturing, utility, transportation, or other OT environments. Security teams responsible for industrial control system infrastructure, network administrators managing industrial Ethernet deployments, and OT security practitioners monitoring CISA ICS advisories should prioritize this vulnerability due to its unauthenticated remote exploitation vector and critical severity rating.
Technical summary
The Planet Technology Planet WGS-804HPT, an industrial managed PoE switch, contains a command injection vulnerability in its HTTP request handling. An unauthenticated attacker can craft malicious HTTP requests that inject and execute arbitrary operating system commands on the device, resulting in complete system compromise. The vulnerability is remotely exploitable without authentication, requires no user interaction, and provides high impact across confidentiality, integrity, and availability dimensions. The affected firmware version is 1.305b210531.
Defensive priority
critical
Recommended defensive actions
- Upgrade affected Planet WGS-804HPT devices to firmware version 1.305b241111 or later as specified by the vendor
- Restrict network access to device management interfaces to trusted administrative hosts only
- Monitor for unauthorized HTTP requests to device management endpoints
- Apply network segmentation to isolate industrial control devices from untrusted networks
- Review CISA ICS recommended practices for defense-in-depth strategies
- Assess device inventory to identify all deployed WGS-804HPT units running affected firmware
- Consider temporary network isolation for devices that cannot be immediately patched
Evidence notes
CISA published advisory ICSA-24-340-02 on December 5, 2024, identifying this vulnerability in Planet Technology's WGS-804HPT industrial switch. The advisory confirms unauthenticated command injection through HTTP requests with remote code execution impact. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H supports the 9.8 critical score. Vendor remediation guidance specifies upgrade to firmware 1.305b241111 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-52320 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-52320
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-52320 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-52320
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-340-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-340-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.