PT-2024-22581 · Infinera · Infinera Hit 7300
Published
2024-09-30
·
Updated
2025-05-30
·
CVE-2024-28809
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Infinera hiT 7300 version 5.60.50
Description
An issue was discovered in the Infinera hiT 7300, where cleartext storage of sensitive passwords in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
Recommendations
For Infinera hiT 7300 version 5.60.50, consider changing the hardcoded credentials and storing passwords securely to prevent unauthorized access. As a temporary workaround, restrict access to the firmware update packages to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infinera Hit 7300