VYPR
Vendor

Ciena

Products
5
CVEs
4
Across products
7
Status
Private

Products

5

Recent CVEs

4
  • CVE-2024-2005CriMar 6, 2024
    risk 0.59cvss 9.0epss 0.00

    In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products.…

  • CVE-2026-5269Jul 14, 2026
    risk 0.00cvss epss 0.00

    In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on…

  • CVE-2026-5270Jul 14, 2026
    risk 0.00cvss epss 0.00

    An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated…

  • CVE-2026-5268Jul 6, 2026
    risk 0.00cvss epss 0.00

    An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem.…