CVE-2024-25661: High severity infinera tnms vulnerability
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25661?
CVE-2024-25661 has been assigned a high severity level due to the potential exposure of user passwords.
How do I fix CVE-2024-25661?
To mitigate CVE-2024-25661, update to the latest version of Infinera TNMS that addresses this vulnerability.
What types of sensitive information are exposed by CVE-2024-25661?
CVE-2024-25661 exposes various users' passwords stored in cleartext in the memory of the TNMS Client.
Who is affected by CVE-2024-25661?
All users of Infinera TNMS version 19.10.3 are affected by CVE-2024-25661.
Can guest OS administrators exploit CVE-2024-25661?
Yes, guest OS administrators can exploit CVE-2024-25661 to obtain users' passwords from memory dumps.