CVE Vulnerabilities

CVE-2024-28809

Cleartext Storage of Sensitive Information

Published: Sep 30, 2024 | Modified: May 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Hit_7300_firmware Nokia 5.60.50 (including) 5.60.50 (including)

Potential Mitigations

References