6.5

CVE-2025-27023

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 
version R6.1.3 allows remote authenticated users to read all OS files 
via crafted CLI commands.


Details: The web interface based management of the Infinera G42 appliance enables the feature of
 executing a restricted set of commands. This feature 
also offers the option to execute a script-file already present on the target
 device. When a non-script or incorrect file is specified, the content 
of the file is shown along with an error message. Due to an execution of the http service with a privileged user all files on the file system can be viewed this way.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NokiaG42 Firmware Version >= 6.1.3 < 7.1
   NokiaG42 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.512
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.