SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-5347

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables.

CRITICAL 9.1EPSS 1.34%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS
1.34% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-327, CWE-347
Affected
korenix/jetnet 5310g firmware · korenix/jetnet 4508 firmware · korenix/jetnet 4508i-w firmware · korenix/jetnet 4508-w firmware · korenix/jetnet 4508if-s firmware · korenix/jetnet 4508if-m firmware · korenix/jetnet 4508if-sw firmware · korenix/jetnet 4508if-mw firmware · korenix/jetnet 4508f-m firmware · korenix/jetnet 4508f-s firmware · korenix/jetnet 4508f-mw firmware · korenix/jetnet 4508f-sw firmware · korenix/jetnet 5620g-4c firmware · korenix/jetnet 5612gp-4f firmware · korenix/jetnet 5612g-4f firmware · korenix/jetnet 5728g-24p-ac-2dc-us firmware · korenix/jetnet 5728g-24p-ac-2dc-eu firmware · korenix/jetnet 6528gf-2ac-eu firmware · korenix/jetnet 6528gf-2ac-us firmware · korenix/jetnet 6528gf-2dc24 firmware · +22 more
Source
office@cyberdanube.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.