9
CVE-2024-25660
- EPSS 0.55%
- Veröffentlicht 01.10.2024 16:15:09
- Zuletzt bearbeitet 03.07.2025 14:34:53
- Erkennungen
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokia ≫ Transcend Network Management System Version 19.10.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.421 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25660
https://www.nokia.com/optical-networks/infinera/