Ciena Corporation

First CVE: Mar 6, 2024Active for: 2 years
4
CVEs Published
More CVEs Published than 12% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
9.2
Avg CVSS Score
Higher Avg CVSS Score than 99% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Ciena Corporation as a CNA, 25.0% affect products that Ciena Corporation develops as a vendor.

25.0%
75.0%
Self-reported: 1Third-party: 3

Of all the CVEs published that affect products developed by Ciena Corporation, 100.0% are self-published by Ciena Corporation as a CNA.

100.0%
Self-published: 1Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Ciena Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2024
2 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Ciena Corporation as a CNA, regardless of affected vendor or product.

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have
Jul 14, 20269.839NONO
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is
Jul 14, 20269.839NONO
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated at
Jul 6, 20269.138NONO
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue
Mar 6, 20248.026NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA4 CVEs
Severity distribution among all CVEs352,231 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None3 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Ciena Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Ciena Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs