The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
The WebDAV service running within the TNMS platform operates with privileges exceeding the necessary minimum (CWE-266 – Incorrect Privilege Assignment). An attacker with only a low-privilege account can, after convincing a user to interact (UI:R), send requests to the WebDAV service and perform operations on system files in the context of an overly privileged process. This mechanism enables access to resources that the attacker should not normally have access to.
An attacker can gain unauthorized read, write, or delete access to files in the network management system, leading to violation of network configuration confidentiality, modification of management data, and potential disruption of network services managed by TNMS.
Apply patches available from the manufacturer according to references. Additionally, it is recommended to restrict network access to the WebDAV service only to trusted hosts and to apply the principle of least privilege for network management service processes.
Infinera TNMS (Transcend Network Management System) version 19.10.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HNokia Transcend Network Management System
APPNokia19.10.3
Related vulnerabilities
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the inter...
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in ...
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows at...
Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell
Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE