TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-2005

CRITICAL
9.0

Description

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue Planet products to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal.

Details CVE

Score CVSS v3.19.0
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie3/6/2024
Derniere modification11/13/2025
Sourcenvd
Observations honeypot0

Produits affectes

ciena:blue_planet_inventory

Faiblesses (CWE)

CWE-269

References

https://www.ciena.com/product-security(7bd90cf1-1651-495e-9ae8-9415fb3c9feb)
https://www.ciena.com/product-security(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.