CVE-2023-5347

Published Jan 9, 2024

Last updated 10 months ago

Overview

Description
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
Source
office@cyberdanube.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-347
office@cyberdanube.com
CWE-347

Social media

Hype score
Not currently trending

Configurations