Ciena Corporation is a network equipment and software vendor focused on optical networking and virtualized infrastructure platforms, with a niche vulnerability footprint centered on its Blue Planet Inventory management product. The observed weakness classes involve improper privilege management and information disclosure, typical of management and control-plane software where access boundaries and data exposure merit particular attention. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ciena Corporation over time
Of all the CVEs published by Ciena Corporation as a CNA, 25.0% affect products that Ciena Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Ciena Corporation, 100.0% are self-published by Ciena Corporation as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2005HIGH
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected.
Blue | Mar 6, 2024 | 8.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ciena Corporation.
Media articles that mention a CVE ID that affects a product developed by Ciena Corporation — matched by CVE ID, not by vendor name.