Impact
This vulnerability is an authentication bypass flaw (CWE-288) located in the default SFTP server component used across several Ciena products. It permits a remote, unauthenticated attacker to bypass normal login checks and gain direct access to the device’s underlying filesystem. If successfully exploited, the attacker can read or alter system files, potentially leading to full compromise of the device.
Affected Systems
Affected devices include the Ciena 6500 S‑Series, Ciena 6500 T‑Series, Ciena CPL and Ciena PTS products, which share a default SFTP server implementation. No specific product version information is supplied in the CVE, so the vulnerability affects the listed product families regardless of the installed version.
Risk and Exploitability
With a CVSS score of 9.1 the flaw is rated Critical. The EPSS score is less than 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is an external connection to the SFTP service, which listens on a network port without requiring authentication. If an attacker can reach the device from outside, they can immediately bypass authentication, read, and modify system files. The risk is heightened for devices exposed to untrusted networks or those that have the SFTP service enabled.
OpenCVE Enrichment