CVE-2025-27024
MEDIUM EPSS 23.6%
Published Jul 2, 202512mo ago · Modified Jun 17, 20261w ago
6.5 CVSS 3.1
Published Jul 2, 2025 12mo ago
Last Modified Jun 17, 2026 1w ago
Description
Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the Network Administrator profile can access the target machine via SFTP with the same credentials used for SSH CLI access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
23.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-280
Affected Products 2
References 2
- euvd.enisa.europa.eu https://euvd.enisa.europa.eu/vulnerability/CVE-2025-27024
- cvcn.gov.it https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27024
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.