CVE-2024-54010
Estado: AnalizadaBaja (3.4)—
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
- Puntuación base: 3.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 13
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-863
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-54010",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-54010",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-09T16:31:10.583426Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-alert@hpe.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.4,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.4,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "Hewlett Packard Enterprise (HPE)",
"product": "AOS-CX",
"versions": [
{
"status": "affected",
"version": "Version 10.10.0000: 10.10.1140 and below",
"versionType": "semver",
"lessThanOrEqual": "<=10.10.1140"
},
{
"status": "affected",
"version": "Version 10.13.0000: 10.13.1060 and below",
"versionType": "semver",
"lessThanOrEqual": "<=10.13.1060"
},
{
"status": "affected",
"version": "Version 10.14.0000: 10.14.1020 and below",
"versionType": "semver",
"lessThanOrEqual": "<=10.14.1020"
},
{
"status": "affected",
"version": "Version 10.15.0000: 10.15.0005 and below",
"versionType": "semver",
"lessThanOrEqual": "<=10.15.0005"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-01-08T21:15:12.900",
"references": [
{
"url": "https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04772.txt",
"tags": [
"Broken Link"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04772en_us&docLocale=en_US",
"tags": [
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad en el componente de firewall de los conmutadores HPE Aruba Networking CX serie 10000. Esta vulnerabilidad podría permitir que un atacante adyacente no autenticado realice un ataque de reenvío de paquetes contra el protocolo ICMP y UDP. Para que este ataque tenga éxito, un atacante necesita una configuración de conmutador que permita el enrutamiento de paquetes (en la capa 3). Las configuraciones que no permiten el enrutamiento del tráfico de red no se ven afectadas. Una explotación exitosa podría permitir que un atacante eluda las políticas de seguridad, lo que podría provocar una exposición no autorizada de datos."
}
],
"lastModified": "2026-09-22T19:55:19.950",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A7E8ECE-C56F-4156-AE93-C119EC0C4F86",
"versionEndExcluding": "10.13.1070",
"versionStartIncluding": "10.10.0000"
},
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF113E06-98F0-4626-BD8F-0EBF766FFE5F",
"versionEndExcluding": "10.14.1030",
"versionStartIncluding": "10.14.0000"
},
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "293AC1A4-5204-45CD-8E68-B057CEDC815A",
"versionEndExcluding": "10.15.1000",
"versionStartIncluding": "10.15.0000"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\\(r8p13a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6B6A0817-A426-4D2C-83F7-4BD3D0088CC5"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\\(r8p14a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "81A92086-F2AA-4137-8EBD-F3A1C9844288"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\\(s0f98a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9F36191B-B250-4210-90E1-2A84123BA10A"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10040_\\(s4r58a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A0F89C29-929B-46F0-AB40-428CA25C3C32"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10040_32p_\\(s4r54a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DAAC47E7-DB94-4AD7-9F77-32D2008677A4"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10040_32p_\\(s4r55a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "81364B89-0FA7-4D66-B7BD-ECC7EB410472"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10040_32p_\\(s4r56a\\):-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "109B5567-C235-4729-9A45-93224D4DD9EB"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security-alert@hpe.com"
}