CVE-2024-54010

CVSS 3.1 Score 3.4 of 10 (low)

Details

Published Jan 8, 2025
Updated: Jan 31, 2025
CWE ID 863

Summary

CVE-2024-54010 is a newly disclosed vulnerability affecting HPE Aruba Networking CX 10000 Series Switches. An unauthenticated adjacent attacker can exploit this flaw, which lies in the firewall component, to perform a packet forwarding attack on ICMP and UDP traffic. This vulnerability is only exploitable when the switch configuration enables packet routing (at layer 3). Configurations devoid of routing capabilities remain unaffected. Successful exploitation may enable the attacker to bypass security policies, potentially leading to unauthorized data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share