MEDIUM
CVE-2025-9912
CVSS
6.3
Description
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
Summary dbcve.org
Nokia SR Linux contains a local privilege escalation vulnerability that allows an authenticated user to execute arbitrary commands with superuser (root) privileges. The vulnerability likely involves improper validation or bypass of privilege separation mechanisms, enabling a standard user to escalate to root access.
Mitigation
Apply vendor-supplied patches for CVE-2025-9912 when available; until then, restrict administrative access to trusted personnel only and monitor for unusual command execution patterns.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.11%
Probability of exploitation in next 30 days
1.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.