CVE-2024-25660: Critical severity infinera tnms vulnerability
Published Oct 1, 2024
·Updated
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
Affected Software
2 affected components
Infinera TNMS
Nokia Transcend Network Management System=19.10.3
Event History
Oct 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25660?
CVE-2024-25660 has a moderate severity rating, enabling unauthorized file operations by low-privileged attackers.
2
How do I fix CVE-2024-25660?
To mitigate CVE-2024-25660, update your Infinera TNMS to the latest version that addresses this vulnerability.
3
What impact does CVE-2024-25660 have on Infinera TNMS?
CVE-2024-25660 allows low-privileged remote attackers to perform unauthorized file operations, potentially compromising the system.
4
Is CVE-2024-25660 a remote or local vulnerability?
CVE-2024-25660 is a remote vulnerability, allowing attackers to exploit it without physical access.
5
Who is affected by CVE-2024-25660?
Organizations using Infinera TNMS version 19.10.3 may be affected by CVE-2024-25660.