Firewall Vulnerability in HPE Aruba Networking CX 10000 Series Switches
CVE-2024-54010
3.4LOW
Key Information:
- Vendor
- HP (HP)
- Status
- Aos-cx
- Vendor
- CVE Published:
- 8 January 2025
Summary
A vulnerability exists within the firewall component of HPE Aruba Networking CX 10000 Series Switches that could enable an unauthenticated adjacent attacker to execute a packet forwarding attack against ICMP and UDP protocols. Successful exploitation allows attackers to bypass security policies, leading to the potential for unauthorized data exposure, especially in switch configurations that permit packet routing at layer 3. Configurations barring network traffic routing remain unaffected.
Affected Version(s)
AOS-CX Version 10.10.0000: 10.10.1140 and below
AOS-CX Version 10.10.0000: 10.10.1140 and below
AOS-CX Version 10.13.0000: 10.13.1060 and below
References
CVSS V3.1
Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Credit
DXC