CVE-2024-54010
Last modified
CVE-2024-54010 is a low-severity vulnerability rated 3.4/10 on the CVSS scale. A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-54010?
How severe is CVE-2024-54010?
How do I fix CVE-2024-54010?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-54005A vulnerability has been identified in COMOS V10.3 (All vers…5.9
- CVE-2024-54006Multiple command injection vulnerabilities exist in the web …7.2
- CVE-2024-54007Multiple command injection vulnerabilities exist in the web …7.2
- CVE-2024-54008An authenticated Remote Code Execution (RCE) vulnerability e…7.2
- CVE-2024-54009Remote authentication bypass vulnerability in HPE Alletra St…4
- CVE-2024-5401Improper control of dynamically-managed code resources vulne…8.8
- CVE-2024-54011Penetration Testing engineers at Amazon have discovered a fl…6.5
- CVE-2024-54012Penetration Testing engineers at Amazon discovered a vulnera…5.3
- CVE-2024-54013Penetration Testing engineers at Amazon have identified a se…8.8
- CVE-2024-54014Improper authorization in handler for custom URL scheme issu…3.6
- CVE-2024-54015A vulnerability has been identified in SIPROTEC 5 6MD84 (CP3…8.7
- CVE-2024-54016Improper Handling of Highly Compressed Data (Data Amplificat…4.3
Are you affected by CVE-2024-54010?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
