ZeroHour

CVE-2023-5347

PoC ×3
CVSS 3.1
9.1 critical
EPSS
1%p70
Published
()
Modified
Description

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

Vendors
korenix
Products
jetnet 5310g firmware, jetnet 4508 firmware, jetnet 4508i-w firmware, jetnet 4508-w firmware, jetnet 4508if-s firmware, jetnet 4508if-m firmware, jetnet 4508if-sw firmware, jetnet 4508if-mw firmware, jetnet 4508f-m firmware, jetnet 4508f-s firmware, jetnet 4508f-mw firmware, jetnet 4508f-sw firmware
Weakness
CWE-327, CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.