CRITICAL · 9.8

CVE-2023-5347

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue a...

Vulnerability Description

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
KorenixJetnet 5310G Firmware2.6
KorenixJetnet 5310G-
KorenixJetnet 4508 Firmware2.3
KorenixJetnet 4508-
KorenixJetnet 4508I-W Firmware1.3
KorenixJetnet 4508I-W-
KorenixJetnet 4508-W Firmware2.3
KorenixJetnet 4508-W-
KorenixJetnet 4508If-S Firmware1.3
KorenixJetnet 4508If-S-
KorenixJetnet 4508If-M Firmware1.3
KorenixJetnet 4508If-M-
KorenixJetnet 4508If-Sw Firmware1.3
KorenixJetnet 4508If-Sw-
KorenixJetnet 4508If-Mw Firmware1.3
KorenixJetnet 4508If-Mw-
KorenixJetnet 4508F-M Firmware2.3
KorenixJetnet 4508F-M-
KorenixJetnet 4508F-S Firmware2.3
KorenixJetnet 4508F-S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-5347?

CVE-2023-5347 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue a...

How severe is CVE-2023-5347?

CVE-2023-5347 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-5347?

Check the references section above for vendor advisories and patch information. Affected products include: Korenix Jetnet 5310G Firmware, Korenix Jetnet 5310G, Korenix Jetnet 4508 Firmware, Korenix Jetnet 4508, Korenix Jetnet 4508I-W Firmware.