Firewall Vulnerability in HPE Aruba Networking CX 10000 Series Switches
CVE-2024-54010

3.4LOW

Key Information:

Vendor
HP (HP)
Status
Aos-cx
Vendor
CVE Published:
8 January 2025

Summary

A vulnerability exists within the firewall component of HPE Aruba Networking CX 10000 Series Switches that could enable an unauthenticated adjacent attacker to execute a packet forwarding attack against ICMP and UDP protocols. Successful exploitation allows attackers to bypass security policies, leading to the potential for unauthorized data exposure, especially in switch configurations that permit packet routing at layer 3. Configurations barring network traffic routing remain unaffected.

Affected Version(s)

AOS-CX Version 10.10.0000: 10.10.1140 and below

AOS-CX Version 10.10.0000: 10.10.1140 and below

AOS-CX Version 10.13.0000: 10.13.1060 and below

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

DXC
.