We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)
Bugpilot (Bug tracking)

Ok

THREATINT CVE Home CVE Diag Help
PUBLISHED

CVE-2024-2005

SAML implementation allows privilege escalation

Reserved:2024-02-29
Published:2024-03-05
Updated:2024-04-03

Description

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue Planet products to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal.



CRITICAL: 9.0CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

early versions
affected

21.10 MR11
unaffected

22.02 MR5
unaffected

22.08 MR4
unaffected

Default status
unaffected

early versions
affected

22.02.03
unaffected

22.08.05
unaffected

22.12.02
unaffected

Default status
unaffected

early versions
affected

22.02.P01.11-R
unaffected

22.08.P01.1-R
unaffected

22.12.P01.2.1-R
unaffected

Default status
unaffected

early versions
affected

22.02 MR5
unaffected

22.12 MR2
unaffected

Credits

Discovered by Prerit Chandok at Comcast finder

References

https://www.ciena.com/product-security

cve.org CVE-2024-2005

nvd.nist.gov CVE-2024-2005

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-2005