The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25660 | Third Party Advisory | 
| https://www.nokia.com/optical-networks/infinera/ | Product | 
Configurations
                    History
                    03 Jul 2025, 14:34
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:nokia:transcend_network_management_system:19.10.3:*:*:*:*:*:*:* | |
| First Time | Nokia Nokia transcend Network Management System | |
| References | () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25660 - Third Party Advisory | |
| References | () https://www.nokia.com/optical-networks/infinera/ - Product | 
25 Mar 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
04 Oct 2024, 13:51
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
01 Oct 2024, 18:35
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-266 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.0 | 
01 Oct 2024, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-10-01 16:15
Updated : 2025-07-03 14:34
NVD link : CVE-2024-25660
Mitre link : CVE-2024-25660
CVE.ORG link : CVE-2024-25660
JSON object : View
Products Affected
                nokia
- transcend_network_management_system
CWE
                
                    
                        
                        CWE-266
                        
            Incorrect Privilege Assignment
