PT-2024-21077 · Infinera · Infinera Tnms

Published

2024-10-01

·

Updated

2025-07-03

·

CVE-2024-25660

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infinera TNMS version 19.10.3
Description The WebDAV service in Infinera TNMS allows a low-privileged remote attacker to conduct unauthorized file operations because it executes with unnecessary privileges.
Recommendations For version 19.10.3, consider restricting access to the WebDAV service until a patch is available. As a temporary workaround, limit the privileges of the WebDAV service to prevent unauthorized file operations.

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-25660

Affected Products

Infinera Tnms