Vulnerability Description
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue Planet products to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ciena | Blue Planet Inventory | <= 22.12 |
Related Weaknesses (CWE)
References
- https://www.ciena.com/product-securityNot Applicable
- https://www.ciena.com/product-securityNot Applicable
FAQ
What is CVE-2024-2005?
CVE-2024-2005 is a vulnerability with a CVSS score of 9.0 (CRITICAL). In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has release...
How severe is CVE-2024-2005?
CVE-2024-2005 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-2005?
Check the references section above for vendor advisories and patch information. Affected products include: Ciena Blue Planet Inventory.