PT-2024-21075 · Infinera · Infinera Tnms

Published

2024-10-01

·

Updated

2025-07-03

·

CVE-2024-25659

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infinera TNMS (Transcend Network Management System) version 19.10.3
Description The issue is related to an insecure default configuration of the internal SFTP server on Linux servers, which allows a remote attacker to access files and directories outside the SFTP user home directory.
Recommendations For Infinera TNMS (Transcend Network Management System) version 19.10.3, consider reconfiguring the internal SFTP server to restrict access to the SFTP user home directory only, until a patch or official fix is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-25659

Affected Products

Infinera Tnms