An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 31 May 2025 06:45:00 +0900

Type Values Removed Values Added
First Time appeared Nokia
Nokia hit 7300
Nokia hit 7300 Firmware
CPEs cpe:2.3:h:nokia:hit_7300:-:*:*:*:*:*:*:*
cpe:2.3:o:nokia:hit_7300_firmware:5.60.50:*:*:*:*:*:*:*
Vendors & Products Nokia
Nokia hit 7300
Nokia hit 7300 Firmware

Tue, 01 Oct 2024 06:30:00 +0900

Type Values Removed Values Added
First Time appeared Infinera
Infinera hit 7300
Weaknesses CWE-312
CWE-798
CPEs cpe:2.3:a:infinera:hit_7300:5.60.50:*:*:*:*:*:*:*
Vendors & Products Infinera
Infinera hit 7300
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Oct 2024 03:15:00 +0900

Type Values Removed Values Added
Description An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-30T20:55:59.795Z

Reserved: 2024-03-11T00:00:00

Link: CVE-2024-28809

cve-icon Vulnrichment

Updated: 2024-09-30T20:55:49.355Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T18:15:05.633

Modified: 2025-05-30T14:50:23.463

Link: CVE-2024-28809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses