CVE-2024-28809

HIGH

Nokia Hit 7300 Firmware - Hard-coded Credentials

Title source: rule
STIX 2.1

Description

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.

Scores

CVSS v3 8.8
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312 CWE-798
Status published
Products (1)
nokia/hit_7300_firmware 5.60.50
Published Sep 30, 2024
Tracked Since Feb 18, 2026