CRITICAL · 9.8

CVE-2017-14027

A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version...

Vulnerability Description

A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. The software uses undocumented hard-coded credentials that may allow an attacker to gain remote access.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
KorenixJetnet5018G Firmware1.4
KorenixJetnet 5018G-
KorenixJetnet5310G Firmware1.4a
KorenixJetnet 5310G-
KorenixJetnet5428G-2G-2Fx Firmware1.4
KorenixJetnet 5428G-2G-2Fx-
KorenixJetnet5628G Firmware1.4
KorenixJetnet 5628G-
KorenixJetnet5628G-R Firmware1.4
KorenixJetnet 5628G-R-
KorenixJetnet5728G-24P Firmware1.4
KorenixJetnet 5728G-24P-
KorenixJetnet5828G Firmware1.1d
KorenixJetnet 5828G-
KorenixJetnet6710G Firmware1.1
KorenixJetnet 6710G-
KorenixJetnet6710G-Hvdc Firmware11e
KorenixJetnet 6710G-Hvdc-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-14027?

CVE-2017-14027 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version...

How severe is CVE-2017-14027?

CVE-2017-14027 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-14027?

Check the references section above for vendor advisories and patch information. Affected products include: Korenix Jetnet5018G Firmware, Korenix Jetnet 5018G, Korenix Jetnet5310G Firmware, Korenix Jetnet 5310G, Korenix Jetnet5428G-2G-2Fx Firmware.