PT-2024-18535 · Ciena · Blue Planet
Prerit Chandok
·
Published
2024-03-05
·
Updated
2025-11-13
·
CVE-2024-2005
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blue Planet products through 22.12
Description
A misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet has released software updates to address this issue.
Recommendations
For Blue Planet products through 22.12, upgrade to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal. As a temporary workaround, consider restricting the use of SAML authentication until a patch is applied.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blue Planet