Filtered by vendor Infinera
Subscriptions
Total
8 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-28812 | 1 Infinera | 1 Hit 7300 | 2024-10-04 | 8.8 High |
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection. | ||||
CVE-2024-28813 | 1 Infinera | 1 Hit 7300 | 2024-10-04 | 8.4 High |
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface. | ||||
CVE-2024-28809 | 1 Infinera | 1 Hit 7300 | 2024-10-04 | 8.8 High |
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials. | ||||
CVE-2024-28810 | 1 Infinera | 1 Hit 7300 | 2024-10-04 | 6.6 Medium |
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files. | ||||
CVE-2024-25660 | 1 Infinera | 1 Tnms | 2024-10-04 | 9 Critical |
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges. | ||||
CVE-2024-25661 | 1 Infinera | 1 Tnms | 2024-10-04 | 7.7 High |
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application. | ||||
CVE-2024-25659 | 1 Infinera | 1 Tnms | 2024-10-04 | 7.2 High |
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory. | ||||
CVE-2024-28807 | 1 Infinera | 1 Hit 7300 | 2024-10-04 | 6.5 Medium |
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application. |
Page 1 of 1.