PT-2024-1168 · Korenix · Korenix Jetnet
S. Dietz
+1
·
Published
2024-01-09
·
Updated
2025-10-08
·
CVE-2023-5376
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Korenix JetNet devices versions prior to 2024/01
Description
The issue is related to an Improper Authentication vulnerability in the TFTP Server component of Korenix JetNet devices. This vulnerability can be exploited by a remote attacker to bypass existing security restrictions, allowing abuse of the TFTP service.
Recommendations
For Korenix JetNet devices older than firmware version 2024/01, update the firmware to version 2024/01 or later to resolve the issue. As a temporary workaround, consider restricting access to the TFTP service until a patch is applied.
Exploit
Fix
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Korenix Jetnet