Ciena Products Authentication Bypass Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. This vulnerability arises from improper handling of HTTP request paths and headers, enabling an unauthenticated attacker to manipulate requests and bypass authentication, along with associated audit logging controls.
Impact
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized access to the affected application or system. This could lead to unauthorized actions being performed or sensitive information being accessed, depending on the application's functionality and data sensitivity.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
