CVE-2023-5347

EUVD-2023-57664
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CyberDanubeCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
korenixjetnet_5310g_firmware
2.6
korenixjetnet_4508_firmware
2.3
korenixjetnet_4508i-w_firmware
1.3
korenixjetnet_4508-w_firmware
2.3
korenixjetnet_4508if-s_firmware
1.3
korenixjetnet_4508if-m_firmware
1.3
korenixjetnet_4508if-sw_firmware
1.3
korenixjetnet_4508if-mw_firmware
1.3
korenixjetnet_4508f-m_firmware
2.3
korenixjetnet_4508f-s_firmware
2.3
korenixjetnet_4508f-mw_firmware
2.3
korenixjetnet_4508f-sw_firmware
2.3
korenixjetnet_5620g-4c_firmware
1.1
korenixjetnet_5612gp-4f_firmware
1.2
korenixjetnet_5612g-4f_firmware
1.2
korenixjetnet_5728g-24p-ac-2dc-us_firmware
2.1
korenixjetnet_5728g-24p-ac-2dc-eu_firmware
2.1
korenixjetnet_6528gf-2ac-eu_firmware
1.0
korenixjetnet_6528gf-2ac-us_firmware
1.0
korenixjetnet_6528gf-2dc24_firmware
1.0
korenixjetnet_6528gf-2dc48_firmware
1.0
korenixjetnet_6528gf-ac-eu_firmware
1.0
korenixjetnet_6528gf-ac-us_firmware
1.0
korenixjetnet_6628xp-4f-us_firmware
1.1
korenixjetnet_6628x-4f-eu_firmware
1.0
korenixjetnet_6728g-24p-ac-2dc-us_firmware
1.1
korenixjetnet_6728g-24p-ac-2dc-eu_firmware
1.1
korenixjetnet_6828gf-2dc48_firmware
1.0
korenixjetnet_6828gf-2dc24_firmware
1.0
korenixjetnet_6828gf-ac-dc24-us_firmware
1.0
korenixjetnet_6828gf-2ac-us_firmware
1.0
korenixjetnet_6828gf-ac-us_firmware
1.0
korenixjetnet_6828gf-2ac-au_firmware
1.0
korenixjetnet_6828gf-ac-dc24-eu_firmware
1.0
korenixjetnet_6828gf-2ac-eu_firmware
1.0
korenixjetnet_6910g-m12_hvdc_firmware
1.0
korenixjetnet_7310g-v2_firmware
1.0
korenixjetnet_7628xp-4f-us_firmware
1.0
korenixjetnet_7628xp-4f-us_firmware
1.1
korenixjetnet_7628xp-4f-eu_firmware
1.0
korenixjetnet_7628xp-4f-eu_firmware
1.1
korenixjetnet_7628x-4f-us_firmware
1.0
korenixjetnet_7628x-4f-eu_firmware
1.0
korenixjetnet_7714g-m12_hvdc_firmware
1.0
𝑥
= Vulnerable software versions