CVE-2024-3281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
09/04/2024
Last modified:
20/02/2026

Description

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:poly_ccx_350:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.3.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_350:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_400:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.3.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_400:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_500:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.3.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_500:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_505:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_505:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_600:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.3.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_600:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_700:*:*:*:*:*:*:*:* 8.0.2.3267 (including) 8.1.3.1301 (excluding)
cpe:2.3:h:hp:poly_ccx_700:-:*:*:*:*:*:*:*