Unrestricted access to OS file system in SFTP service in Infinera G42
version R6.1.3 allows remote authenticated users to read/write OS files
via SFTP connections.
Details: Account members of the Network Administrator profile can access the
target machine via SFTP with the same credentials used for SSH CLI
access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-274 | CWE-280 |
Wed, 02 Jul 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. Details: Account members of the Network Administrator profile can access the target machine via SFTP with the same credentials used for SSH CLI access and are able to read all files according to the OS permission instead of remaining inside the chrooted directory position. | |
Title | Improper File Access in Infinera G42 | |
Weaknesses | CWE-274 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ENISA
Published: 2025-07-02T09:38:32.141Z
Updated: 2025-07-02T13:07:51.401Z
Reserved: 2025-02-18T06:59:55.889Z
Link: CVE-2025-27024

Updated: 2025-07-02T13:06:42.902Z

Status : Awaiting Analysis
Published: 2025-07-02T10:15:22.730
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-27024

No data.