---
id: CVE-2024-54010
title: >-
  A vulnerability in the firewall component of HPE Aruba Networking CX 10000
  Series Switches  exists
summary: >-
  A vulnerability in the firewall component of HPE Aruba Networking CX 10000
  Series Switches  exists. It could allow an unauthenticated adjacent attacker
  to conduct a packet  forwarding attack against the ICMP and UDP protocol. For
  this at…
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: hpe
product: arubaos-cx
affected:
  - 'arubaos-cx >= 10.10.0000, < 10.13.1070'
  - 'arubaos-cx >= 10.14.0000, < 10.14.1030'
  - 'arubaos-cx >= 10.15.0000, < 10.15.1000'
patched:
  - arubaos-cx 10.15.1000
published: '2025-01-08'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:55:19.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-54010'
references:
  - url: >-
      https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04772.txt
    label: security-alert@hpe.com
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04772en_us&docLocale=en_US
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00229
epssPercentile: 0.13968
ingestedAt: '2026-09-22T19:09:09.961Z'
---

## Overview

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches  exists. It could allow an unauthenticated adjacent attacker to conduct a packet  forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.

## Affected

- `arubaos-cx >= 10.10.0000, < 10.13.1070`
- `arubaos-cx >= 10.14.0000, < 10.14.1030`
- `arubaos-cx >= 10.15.0000, < 10.15.1000`

## Remediation

Upgrade past the affected range:

- `arubaos-cx 10.15.1000`
