Vulnerability Description
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Korenix | Jetnet 5310G Firmware | 2.6 |
| Korenix | Jetnet 5310G | - |
| Korenix | Jetnet 4508 Firmware | 2.3 |
| Korenix | Jetnet 4508 | - |
| Korenix | Jetnet 4508I-W Firmware | 1.3 |
| Korenix | Jetnet 4508I-W | - |
| Korenix | Jetnet 4508-W Firmware | 2.3 |
| Korenix | Jetnet 4508-W | - |
| Korenix | Jetnet 4508If-S Firmware | 1.3 |
| Korenix | Jetnet 4508If-S | - |
| Korenix | Jetnet 4508If-M Firmware | 1.3 |
| Korenix | Jetnet 4508If-M | - |
| Korenix | Jetnet 4508If-Sw Firmware | 1.3 |
| Korenix | Jetnet 4508If-Sw | - |
| Korenix | Jetnet 4508If-Mw Firmware | 1.3 |
| Korenix | Jetnet 4508If-Mw | - |
| Korenix | Jetnet 4508F-M Firmware | 2.3 |
| Korenix | Jetnet 4508F-M | - |
| Korenix | Jetnet 4508F-S Firmware | 2.3 |
| Korenix | Jetnet 4508F-S | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-UnauthenticateExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2024/Jan/11ExploitMailing ListThird Party Advisory
- https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/ExploitThird Party Advisory
- https://www.beijerelectronics.com/en/support/Help___online?docId=69947Vendor Advisory
- http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-UnauthenticateExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2024/Jan/11ExploitMailing ListThird Party Advisory
- https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/ExploitThird Party Advisory
- https://www.beijerelectronics.com/en/support/Help___online?docId=69947Vendor Advisory
FAQ
What is CVE-2023-5347?
CVE-2023-5347 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue a...
How severe is CVE-2023-5347?
CVE-2023-5347 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-5347?
Check the references section above for vendor advisories and patch information. Affected products include: Korenix Jetnet 5310G Firmware, Korenix Jetnet 5310G, Korenix Jetnet 4508 Firmware, Korenix Jetnet 4508, Korenix Jetnet 4508I-W Firmware.