CVE-2024-25661
Last modified
CVE-2024-25661 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Transcend Network Management System | 19.10.3 |
References
- https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25661Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-25661?
How severe is CVE-2024-25661?
How do I fix CVE-2024-25661?
Are you affected by CVE-2024-25661?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
