Impact
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite, Manage Control Plan, and Blue Planet products. The flaw stems from improper handling of HTTP request paths and headers, allowing an unauthenticated attacker to craft requests that circumvent both authentication and the associated audit logging controls. The result is that an attacker can gain unauthorized access to the impacted systems and perform any actions allowed for an authenticated user without being recorded in logs, potentially exposing sensitive data or configuration information.
Affected Systems
The affected families include Blue Planet Inventory, Blue Planet Orchestration, Blue Planet Route Optimization & Analysis, Blue Planet Unified Assurance & Analytics, Ciena Navigator NCS, Ciena Manage Control Plan (MCP), and Ciena Planner Plus OnPrem. While the specific vulnerable releases are not enumerated, the vendor has issued a remediation schedule. For each upgrade to the listed remediated releases: BP Inventory ≥24.08, 24.04.100, 23.12.500, 23.08.400, 23.04.800; BP Orchestration ≥24.08, 24.04.3 MR3, 23.12.4 MR4, 23.08.5 MR5, 23.04.4 MR3; BP Route Optimization & Analysis ≥24.08, 24.04.2‑3‑R, 23.12.2.1‑R, 23.08.2.-1‑R, 23.04.P02‑1‑R; BP Unified Assurance & Analytics ≥24.08, 24.04.MR2, 23.12.MR.02; MCP 8.0‑P04, 7.2‑P07; Planner Plus OnPrem ≥4.2, 4.1‑P01.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity, while an EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at the present time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote network-based, with an attacker sending specially crafted HTTP requests that exploit the incorrect path and header handling to bypass authentication. Successful exploitation would allow unauthenticated access to the affected system and negates audit logging, thereby facilitating further malicious actions without forensic trace.
OpenCVE Enrichment