PT-2024-22580 · Infinera · Infinera Hit 7300

Published

2024-09-30

·

Updated

2024-11-06

·

CVE-2024-28808

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Infinera hiT 7300 version 5.60.50
Description An issue was discovered in the web interface of the affected software, which contains hidden functionality. This allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.
Recommendations For Infinera hiT 7300 version 5.60.50, consider restricting access to the web interface until a fix is available. As a temporary workaround, limit the use of undocumented web applications to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-28808

Affected Products

Infinera Hit 7300