CVE-2024-48871: Planet Technology Planet WGS-804HPT Stack-based Buffer Overflow

9.8 CVSS

Description

The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly check input size before copying data to the stack, potentially allowing remote code execution.

Classification

CVE ID: CVE-2024-48871

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

Affected Products

Vendor: Planet Technology

Product: Planet WGS-804HPT

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.cisa.gov/news-events/ics-advisories/icsa-24-340-02
https://www.planet.com.tw/en/support/downloads?method=keyword&keyword=v1.305b241111

Timeline