CVE-2025-0980: JSON RPC authentication bypass in Nokia SR Linux
Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0980?
CVE-2025-0980 is classified as a high-severity vulnerability due to its potential for unauthorized access.
How does CVE-2025-0980 affect Nokia SR Linux?
CVE-2025-0980 affects Nokia SR Linux by allowing unauthorized access to the JSON-RPC service without valid authentication.
What are the potential consequences of exploiting CVE-2025-0980?
Exploiting CVE-2025-0980 can lead to unauthorized data access and manipulation through the JSON-RPC service.
How do I fix CVE-2025-0980?
To fix CVE-2025-0980, apply the latest security patch provided by Nokia for SR Linux.
Is there a workaround for CVE-2025-0980 until a fix is applied?
Yes, temporarily restricting access to the JSON-RPC service can serve as a workaround for CVE-2025-0980.