PT-2024-21074 · Infinera · Infinera Tnms Server
Published
2024-10-01
·
Updated
2024-11-22
·
CVE-2024-25658
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Infinera TNMS Server version 19.10.3
Description
The issue allows attackers with access to the database or exported configuration files to obtain SNMP users' usernames and passwords in cleartext. This occurs due to the cleartext storage of passwords in the Infinera TNMS Server.
Recommendations
For version 19.10.3, consider restricting access to the database and exported configuration files to minimize the risk of exploitation. As a temporary workaround, restrict the use of SNMP until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinera Tnms Server