CVE-2024-25658

Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25658 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nokia:transcend_network_management_system:19.10.3:*:*:*:*:*:*:*

History

10 Jul 2025, 21:02

Type Values Removed Values Added
First Time Nokia transcend Network Management System
Nokia
References () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25658 - () https://www.cvcn.gov.it/cvcn/cve/CVE-2024-25658 - Third Party Advisory
CPE cpe:2.3:a:nokia:transcend_network_management_system:19.10.3:*:*:*:*:*:*:*

22 Nov 2024, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-312

04 Oct 2024, 13:51

Type Values Removed Values Added
Summary
  • (es) El almacenamiento de contraseñas en texto plano en Infinera TNMS (Transcend Network Management System) Server 19.10.3 permite a los atacantes (con acceso a la base de datos o a los archivos de configuración exportados) obtener los nombres de usuario y las contraseñas de los usuarios de SNMP en texto plano.

01 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 15:15

Updated : 2025-07-10 21:02


NVD link : CVE-2024-25658

Mitre link : CVE-2024-25658

CVE.ORG link : CVE-2024-25658


JSON object : View

Products Affected

nokia

  • transcend_network_management_system
CWE
CWE-312

Cleartext Storage of Sensitive Information