CVE-2024-3281

HIGH

HP Poly CCX 350/400/500/505/600/700 >=8.0.2.3267 <8.1.3.1301 - Unauthenticated Critical Function Access

Title source: llm
STIX 2.1

Description

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.

Scores

CVSS v3 8.8
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (6)
hp/poly_ccx_350 8.0.2.3267 - 8.1.3.1301
hp/poly_ccx_400 8.0.2.3267 - 8.1.3.1301
hp/poly_ccx_500 8.0.2.3267 - 8.1.3.1301
hp/poly_ccx_505 8.0.2.3267 - 8.1.1301
hp/poly_ccx_600 8.0.2.3267 - 8.1.3.1301
hp/poly_ccx_700 8.0.2.3267 - 8.1.3.1301
Published Apr 09, 2024
Tracked Since Feb 18, 2026