CVE Vulnerabilities

CVE-2024-25658

Cleartext Storage of Sensitive Information

Published: Oct 01, 2024 | Modified: Jul 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users usernames and passwords in cleartext.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Transcend_network_management_system Nokia 19.10.3 (including) 19.10.3 (including)

Potential Mitigations

References