CVE-2025-27021

EUVD-2025-19698
The misconfiguration in the sudoers configuration of the operating system in
 Infinera G42 version R6.1.3 allows low privileged OS users to 
read/write physical memory via devmem command line tool. 
This could 
allow sensitive information disclosure, denial of service, and privilege 
escalation by tampering with kernel memory.


Details: The output of "sudo -l" reports the presence of "devmem" command 
executable as super user without using a password. This command allows 
to read and write an arbitrary memory area of the target device, 
specifying an absolute address.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
ENISACNA
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
nokiag42_firmware
6.1.3 ≤
𝑥
< 7.1
𝑥
= Vulnerable software versions