6.5

CVE-2025-27024

Unrestricted access to OS file system in SFTP service in Infinera G42 
version R6.1.3 allows remote authenticated users to read/write OS files 
via SFTP connections.


Details: Account members of the Network Administrator profile can access the 
target machine via SFTP with the same credentials used for SSH CLI 
access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NokiaG42 Firmware Version >= 6.1.3 < 8.0
   NokiaG42 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.244
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-280 Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.