A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.
References
| Link | Resource |
|---|---|
| https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 | Vendor Advisory |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt | Exploit Third Party Advisory |
| https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 | Vendor Advisory |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
20 Feb 2026, 21:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 - Vendor Advisory | |
| References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt - Exploit, Third Party Advisory | |
| First Time |
Hp poly Ccx 700
Hp poly Ccx 350 Hp poly Ccx 600 Hp poly Ccx 400 Hp poly Ccx 500 Hp Hp poly Ccx 505 |
|
| CPE | cpe:2.3:o:hp:poly_ccx_400:*:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_400:-:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_505:-:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_350:-:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_700:-:*:*:*:*:*:*:* cpe:2.3:o:hp:poly_ccx_505:*:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_500:-:*:*:*:*:*:*:* cpe:2.3:o:hp:poly_ccx_500:*:*:*:*:*:*:*:* cpe:2.3:o:hp:poly_ccx_350:*:*:*:*:*:*:*:* cpe:2.3:h:hp:poly_ccx_600:-:*:*:*:*:*:*:* cpe:2.3:o:hp:poly_ccx_700:*:*:*:*:*:*:*:* cpe:2.3:o:hp:poly_ccx_600:*:*:*:*:*:*:*:* |
21 Nov 2024, 09:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 - | |
| References | () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt - |
20 Nov 2024, 18:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-306 |
10 Apr 2024, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Apr 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-04-09 16:15
Updated : 2026-02-20 21:14
NVD link : CVE-2024-3281
Mitre link : CVE-2024-3281
CVE.ORG link : CVE-2024-3281
JSON object : View
Products Affected
hp
- poly_ccx_600
- poly_ccx_400
- poly_ccx_500
- poly_ccx_505
- poly_ccx_350
- poly_ccx_700
CWE
CWE-306
Missing Authentication for Critical Function
