VulnerabilityAnalyzed
CVE-2024-28809
Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
HIGH 8.8EPSS 0.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312, CWE-798
- Affected
- nokia/hit 7300 firmware
- Source
- cve@mitre.org
References
- https://www.cvcn.gov.it/cvcn/cve/CVE-2024-28809Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.