CVE-2023-5347

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables.This issue affects JetNet devices older than firmware version 2024/01.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CyberDanubeCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
korenixjetnet_5310g_firmware
2.6
korenixjetnet_4508_firmware
2.3
korenixjetnet_4508i-w_firmware
1.3
korenixjetnet_4508-w_firmware
2.3
korenixjetnet_4508if-s_firmware
1.3
korenixjetnet_4508if-m_firmware
1.3
korenixjetnet_4508if-sw_firmware
1.3
korenixjetnet_4508if-mw_firmware
1.3
korenixjetnet_4508f-m_firmware
2.3
korenixjetnet_4508f-s_firmware
2.3
korenixjetnet_4508f-mw_firmware
2.3
korenixjetnet_4508f-sw_firmware
2.3
korenixjetnet_5620g-4c_firmware
1.1
korenixjetnet_5612gp-4f_firmware
1.2
korenixjetnet_5612g-4f_firmware
1.2
korenixjetnet_5728g-24p-ac-2dc-us_firmware
2.1
korenixjetnet_5728g-24p-ac-2dc-eu_firmware
2.1
korenixjetnet_6528gf-2ac-eu_firmware
1.0
korenixjetnet_6528gf-2ac-us_firmware
1.0
korenixjetnet_6528gf-2dc24_firmware
1.0
korenixjetnet_6528gf-2dc48_firmware
1.0
korenixjetnet_6528gf-ac-eu_firmware
1.0
korenixjetnet_6528gf-ac-us_firmware
1.0
korenixjetnet_6628xp-4f-us_firmware
1.1
korenixjetnet_6628x-4f-eu_firmware
1.0
korenixjetnet_6728g-24p-ac-2dc-us_firmware
1.1
korenixjetnet_6728g-24p-ac-2dc-eu_firmware
1.1
korenixjetnet_6828gf-2dc48_firmware
1.0
korenixjetnet_6828gf-2dc24_firmware
1.0
korenixjetnet_6828gf-ac-dc24-us_firmware
1.0
korenixjetnet_6828gf-2ac-us_firmware
1.0
korenixjetnet_6828gf-ac-us_firmware
1.0
korenixjetnet_6828gf-2ac-au_firmware
1.0
korenixjetnet_6828gf-ac-dc24-eu_firmware
1.0
korenixjetnet_6828gf-2ac-eu_firmware
1.0
korenixjetnet_6910g-m12_hvdc_firmware
1.0
korenixjetnet_7310g-v2_firmware
1.0
korenixjetnet_7628xp-4f-us_firmware
1.0
korenixjetnet_7628xp-4f-us_firmware
1.1
korenixjetnet_7628xp-4f-eu_firmware
1.0
korenixjetnet_7628xp-4f-eu_firmware
1.1
korenixjetnet_7628x-4f-us_firmware
1.0
korenixjetnet_7628x-4f-eu_firmware
1.0
korenixjetnet_7714g-m12_hvdc_firmware
1.0
𝑥
= Vulnerable software versions