CVE-2024-25659: Path Traversal
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25659?
CVE-2024-25659 is classified as a high severity vulnerability due to the potential for remote file access.
How do I fix CVE-2024-25659?
To fix CVE-2024-25659, reconfigure the SFTP server to limit user access strictly to their home directories.
What types of systems are affected by CVE-2024-25659?
CVE-2024-25659 affects Infinera TNMS version 19.10.3 running on Linux servers.
What are the potential impacts of CVE-2024-25659?
The potential impacts of CVE-2024-25659 include unauthorized access to sensitive files and directories on the server.
Is there a patch available for CVE-2024-25659?
As of now, it is advised to follow best practices for server configuration while awaiting an official patch for CVE-2024-25659.