CVE-2025-27021
EUVD-2025-1969802.07.2025, 09:15
The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via devmem command line tool. This could allow sensitive information disclosure, denial of service, and privilege escalation by tampering with kernel memory. Details: The output of "sudo -l" reports the presence of "devmem" command executable as super user without using a password. This command allows to read and write an arbitrary memory area of the target device, specifying an absolute address.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nokia | g42_firmware | 6.1.3 ≤ 𝑥 < 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration