CVE-2024-25660
CVSS 3.1 Score 9 of 10 (high)
Details
Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 266
Summary
CVE-2024-25660 is a newly disclosed vulnerability affecting the WebDAV service in Infinera TNMS (Transcend Network Management System) version 19.10.3. This issue grants low-privileged remote attackers the ability to perform unauthorized file operations, due to the service running with unnecessarily elevated privileges. Successful exploitation could lead to data manipulation, disclosure, or other unintended consequences. It is crucial for organizations using this version of Infinera TNMS to update as soon as a patch is available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TN - MS