CVE-2024-3281

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hp:poly_ccx_350:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_350:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hp:poly_ccx_400:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_400:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hp:poly_ccx_500:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_500:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hp:poly_ccx_505:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_505:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hp:poly_ccx_600:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_600:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hp:poly_ccx_700:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_700:-:*:*:*:*:*:*:*

History

20 Feb 2026, 21:14

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 - () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 - Vendor Advisory
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt - Exploit, Third Party Advisory
First Time Hp poly Ccx 700
Hp poly Ccx 350
Hp poly Ccx 600
Hp poly Ccx 400
Hp poly Ccx 500
Hp
Hp poly Ccx 505
CPE cpe:2.3:o:hp:poly_ccx_400:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_400:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_505:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_350:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_700:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_505:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_500:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_500:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_350:*:*:*:*:*:*:*:*
cpe:2.3:h:hp:poly_ccx_600:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_700:*:*:*:*:*:*:*:*
cpe:2.3:o:hp:poly_ccx_600:*:*:*:*:*:*:*:*

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 - () https://support.hp.com/us-en/document/ish_10388650-10388701-16/hpsbpy03929 -
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt -

20 Nov 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-306

10 Apr 2024, 07:15

Type Values Removed Values Added
References
  • () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-003.txt -

09 Apr 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-09 16:15

Updated : 2026-02-20 21:14


NVD link : CVE-2024-3281

Mitre link : CVE-2024-3281

CVE.ORG link : CVE-2024-3281


JSON object : View

Products Affected

hp

  • poly_ccx_600
  • poly_ccx_400
  • poly_ccx_500
  • poly_ccx_505
  • poly_ccx_350
  • poly_ccx_700
CWE
CWE-306

Missing Authentication for Critical Function