CVE-2023-5347

Published Jan 9, 2024

Last updated 6 months ago

Overview

Description
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
Source
office@cyberdanube.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity
CRITICAL

Weaknesses

office@cyberdanube.com
CWE-347
nvd@nist.gov
CWE-347

Social media

Hype score
Not currently trending

Configurations