Vulnerability Description
Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the Network Administrator profile can access the target machine via SFTP with the same credentials used for SSH CLI access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokia | G42 Firmware | >= 6.1.3, < 8.0 |
| Nokia | G42 | - |
Related Weaknesses (CWE)
References
- https://euvd.enisa.europa.eu/vulnerability/CVE-2025-27024Third Party Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27024Third Party Advisory
FAQ
What is CVE-2025-27024?
CVE-2025-27024 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the ...
How severe is CVE-2025-27024?
CVE-2025-27024 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27024?
Check the references section above for vendor advisories and patch information. Affected products include: Nokia G42 Firmware, Nokia G42.