CRITICAL🇵🇱 Wersja polska

CVE-2024-25660

CVSS 9.0v3.1pub. 2024-10-01upd. 2025-07-03

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

🤖 AI Analysis
How it works

The WebDAV service running within the TNMS platform operates with privileges exceeding the necessary minimum (CWE-266 – Incorrect Privilege Assignment). An attacker with only a low-privilege account can, after convincing a user to interact (UI:R), send requests to the WebDAV service and perform operations on system files in the context of an overly privileged process. This mechanism enables access to resources that the attacker should not normally have access to.

Impact

An attacker can gain unauthorized read, write, or delete access to files in the network management system, leading to violation of network configuration confidentiality, modification of management data, and potential disruption of network services managed by TNMS.

Mitigation & patch

Apply patches available from the manufacturer according to references. Additionally, it is recommended to restrict network access to the WebDAV service only to trusted hosts and to apply the principle of least privilege for network management service processes.

Who is affected

Infinera TNMS (Transcend Network Management System) version 19.10.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Nokia Transcend Network Management System

    APP
    Nokia
    19.10.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-25659HIGH7.2same product

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the inter...

CVE-2024-25661HIGH7.7same product

In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in ...

CVE-2024-25658MEDIUM6.5same product

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows at...

CVE-2025-27019CRITICAL9.8PL ✓same vendor

Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell

CVE-2025-27020CRITICAL9.8PL ✓same vendor

Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE