Misconfiguration in Infinera G42 Allows Unprivileged Users to Manipulate Memory
CVE-2025-27021

7HIGH

Key Information:

Vendor

Infinera

Status
Vendor
CVE Published:
2 July 2025

What is CVE-2025-27021?

A misconfiguration in the sudoers settings of Infinera G42 version R6.1.3 permits low-privileged users to access and manipulate physical memory using the 'devmem' command line tool. This misconfiguration allows unauthorized users to read from and write to arbitrary memory addresses, which could lead to information disclosure, potential denial of service, and escalate privileges by tampering with kernel memory. The compromised sudo permissions pose a significant risk to system integrity and security, necessitating immediate attention and remediation.

Affected Version(s)

G42 6.1.3 < 7.1

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Agenzia per la Cybersicurezza Nazionale
.