CVE-2025-27021

HIGH

Infinera G42 R6.1.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via devmem command line tool. This could allow sensitive information disclosure, denial of service, and privilege escalation by tampering with kernel memory. Details: The output of "sudo -l" reports the presence of "devmem" command executable as super user without using a password. This command allows to read and write an arbitrary memory area of the target device, specifying an absolute address.

References (2)

Core 2
Core References
Third Party Advisory government-resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27021

Scores

CVSS v3 7.0
EPSS 0.0013
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
nokia/g42_firmware 6.1.3 - 7.1
Published Jul 02, 2025
Tracked Since Feb 18, 2026