Impact
The vulnerability is an unauthenticated access flaw in an event‑streaming API that does not enforce authentication. This allows an attacker to receive the event stream, which can contain sensitive session tokens, potentially granting further access. It is categorized as CWE‑306, reflecting insufficient authentication.
Affected Systems
The flaw affects Ciena Navigator NCS. Versions 8.0‑P06B and later, 8.1‑P06A and later, 8.2‑P07 and later, 9.0‑P05B and later, 9.1‑P05A and later, 9.2‑P02A and later, and 10.0‑P01C and later are all affected.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity. EPSS information is not available and the vulnerability is not listed in CISA KEV, but the lack of authentication control makes it highly exploitable to anyone with network connectivity to the affected service. The impact of exposing session tokens can lead to unauthorized access to the system and connected resources.
OpenCVE Enrichment