PT-2024-22579 · Infinera · Infinera Hit 7300

Published

2024-09-30

·

Updated

2025-05-30

·

CVE-2024-28807

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Infinera hiT 7300 version 5.60.50
Description An issue was discovered in the @CT desktop management application, where sensitive information is stored in cleartext in the application's memory. This allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.
Recommendations For Infinera hiT 7300 version 5.60.50, consider restricting access to the @CT desktop management application to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-28807

Affected Products

Infinera Hit 7300