CVE-2024-45367 describes a critical authentication bypass vulnerability in the web server of ONS-S8 Spectra Aggregation Switches, allowing unauthenticated attackers to gain full access without a password. This flaw carries a CVSS score of 9.1 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality and integrity. While not currently listed on CISA's KEV catalog, the vulnerability has garnered significant community attention with one mention and one media article, indicating awareness within the cybersecurity community. There is no public exploit code available for Metasploit, Nuclei, or ExploitDB at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Optigo Networks | ONS-S8 Spectra Aggregation Switch | >= 0, <= 1.3.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.