7.8

CVE-2025-27021

The misconfiguration in the sudoers configuration of the operating system in
 Infinera G42 version R6.1.3 allows low privileged OS users to 
read/write physical memory via devmem command line tool. 
This could 
allow sensitive information disclosure, denial of service, and privilege 
escalation by tampering with kernel memory.


Details: The output of "sudo -l" reports the presence of "devmem" command 
executable as super user without using a password. This command allows 
to read and write an arbitrary memory area of the target device, 
specifying an absolute address.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NokiaG42 Firmware Version >= 6.1.3 < 7.1
   NokiaG42 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.