Misconfiguration in Infinera G42 Allows Unprivileged Users to Manipulate Memory
CVE-2025-27021
7HIGH
What is CVE-2025-27021?
A misconfiguration in the sudoers settings of Infinera G42 version R6.1.3 permits low-privileged users to access and manipulate physical memory using the 'devmem' command line tool. This misconfiguration allows unauthorized users to read from and write to arbitrary memory addresses, which could lead to information disclosure, potential denial of service, and escalate privileges by tampering with kernel memory. The compromised sudo permissions pose a significant risk to system integrity and security, necessitating immediate attention and remediation.
Affected Version(s)
G42 6.1.3 < 7.1