CVE-2025-9912: A local privilege escalation vulnerability in Nokia SR Linux
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to Nokia SR Linux management interfaces and systems to trusted administrative hosts and networks using firewall rules, ACLs, or network segmentation to limit which authenticated users can reach the device.
- Compensating control
Apply least-privilege for local accounts: disable or remove unused accounts, restrict interactive login to administrators only, and limit sudo/privilege escalation rights to only those users that require them.
- Operational
Audit existing user accounts and privilege assignments on affected systems, review authentication logs for signs of suspicious activity or attempted privilege escalation, and investigate any anomalies. If compromise is suspected, rotate credentials for affected accounts and escalate incident response procedures as appropriate.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9912?
The severity of CVE-2025-9912 is classified as medium with a CVSS score of 6.3.
How can I fix CVE-2025-9912?
To address CVE-2025-9912, ensure that you update your Nokia SR Linux software to the latest version provided by Nokia that includes the relevant patches.
What does CVE-2025-9912 affect?
CVE-2025-9912 affects Nokia SR Linux, an operating system used in Nokia network devices.
What can attackers do with CVE-2025-9912?
An attacker who successfully exploits CVE-2025-9912 can execute arbitrary commands with superuser privileges on the affected system.
Who is impacted by CVE-2025-9912?
Authenticated users of Nokia SR Linux are impacted by CVE-2025-9912 if they can exploit this local privilege escalation vulnerability.