VendorsNokiahit_7300all versions
Vulnerabilities

Nokia hiT 7300 Multi-Haul Transport Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-28812
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.
Published 2024-09-30 · Analyzed
8.8EPSS 0.003
CVE-2024-28809
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
Published 2024-09-30 · Analyzed
8.8EPSS 0.002
CVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.
Published 2024-09-30 · Analyzed
8.4EPSS 0.002
CVE-2024-28810
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.
Published 2024-09-30 · Analyzed
6.6EPSS 0.002
CVE-2024-28807
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.
Published 2024-09-30 · Analyzed
6.5EPSS 0.001
CVE-2024-28811
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
Published 2024-09-30 · Analyzed
3.3EPSS 0.003
CVE-2024-28808
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.
Published 2024-09-30 · Analyzed
2.7EPSS 0.004