3.4

CVE-2024-54010

Unauthenticated Traffic Handling Flaw Allows Packet Leakage on HPE Aruba Networking CX 10000 series switches

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches  exists. It could allow an unauthenticated adjacent attacker to conduct a packet  forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version >= 10.10.0000 < 10.13.1070
Hpe ≫ Arubaos-cx Version >= 10.14.0000 < 10.14.1030
Hpe ≫ Arubaos-cx Version >= 10.15.0000 < 10.15.1000
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.154
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.4 1.6 1.4
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
HPE 3.4 1.6 1.4
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04772.txt
Broken Link
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04772en_us&docLocale=en_US
Vendor Advisory