CVE-2024-54010
CVSS 3.1 Score 3.4 of 10 (low)
Details
Summary
CVE-2024-54010 is a newly disclosed vulnerability affecting HPE Aruba Networking CX 10000 Series Switches. An unauthenticated adjacent attacker can exploit this flaw, which lies in the firewall component, to perform a packet forwarding attack on ICMP and UDP traffic. This vulnerability is only exploitable when the switch configuration enables packet routing (at layer 3). Configurations devoid of routing capabilities remain unaffected. Successful exploitation may enable the attacker to bypass security policies, potentially leading to unauthorized data exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.