CVE-2024-28812

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/09/2024
Last modified:
30/05/2025

Description

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nokia:hit_7300_firmware:5.60.50:*:*:*:*:*:*:*
cpe:2.3:h:nokia:hit_7300:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools