CVE-2023-5347
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
09/01/2024
Last modified:
08/10/2025
Description
An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:korenix:jetnet_5310g_firmware:2.6:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_5310g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508_firmware:2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508i-w_firmware:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508i-w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508-w_firmware:2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508-w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508if-s_firmware:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508if-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508if-m_firmware:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508if-m:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508if-sw_firmware:1.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:korenix:jetnet_4508if-sw:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:korenix:jetnet_4508if-mw_firmware:1.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
- http://seclists.org/fulldisclosure/2024/Jan/11
- https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/
- https://www.beijerelectronics.com/en/support/Help___online?docId=69947
- http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
- http://seclists.org/fulldisclosure/2024/Jan/11
- https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/
- https://www.beijerelectronics.com/en/support/Help___online?docId=69947



