7.7
CVE-2024-25661
- EPSS 0.02%
- Veröffentlicht 01.10.2024 15:15:07
- Zuletzt bearbeitet 10.07.2025 21:02:52
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokia ≫ Transcend Network Management System Version19.10.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.021 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.7 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.