9.8
CVE-2025-27019
- EPSS 0.06%
- Veröffentlicht 08.12.2025 09:22:19
- Zuletzt bearbeitet 22.12.2025 18:55:45
- Quelle a6d3dc9e-0591-4a13-bce7-0f5b31
- CVE-Watchlists
- Unerledigt
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nokia ≫ Infinera Mtc-9 Firmware Version >= 22.1.1.0275 < 23.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.187 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.