PT-2024-1168 · Korenix · Korenix Jetnet

S. Dietz

+1

·

Published

2024-01-09

·

Updated

2025-10-08

·

CVE-2023-5376

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Korenix JetNet devices versions prior to 2024/01
Description The issue is related to an Improper Authentication vulnerability in the TFTP Server component of Korenix JetNet devices. This vulnerability can be exploited by a remote attacker to bypass existing security restrictions, allowing abuse of the TFTP service.
Recommendations For Korenix JetNet devices older than firmware version 2024/01, update the firmware to version 2024/01 or later to resolve the issue. As a temporary workaround, consider restricting access to the TFTP service until a patch is applied.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00494
CVE-2023-5376

Affected Products

Korenix Jetnet