CVE-2024-2005: SAML implementation allows privilege escalation
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected.
Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue Planet products to the latest software version as soon as possible. The software updates can be downloaded from the Ciena Support Portal.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2005?
CVE-2024-2005 has a severity associated with privilege escalation due to a misconfiguration in the SAML implementation.
How do I fix CVE-2024-2005?
To fix CVE-2024-2005, update to the latest software versions provided by Blue Planet that address this vulnerability.
Who is affected by CVE-2024-2005?
CVE-2024-2005 affects users of Blue Planet products that utilize SAML authentication and are running versions up to 22.12.
What products are impacted by CVE-2024-2005?
The impacted products are those within the Ciena Blue Planet suite that utilize SAML authentication configurations.
Is there a workaround for CVE-2024-2005?
The best approach for CVE-2024-2005 is to apply the software updates released by Blue Planet as a workaround.