The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25660 | third party advisory |
https://www.nokia.com/optical-networks/infinera/ | product |