PT-2024-5662 · Korenix · Korenix Jetport 5601V3+1

S. Dietz

+1

·

Published

2024-04-01

·

Updated

2024-08-07

·

CVE-2024-7395

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Korenix JetPort versions 1.2 and earlier Korenix JetPort 5601v3 versions through 1.2
Description The issue is related to weaknesses in the authentication procedure of the Korenix JetPort serial device server. It may allow a remote attacker to bypass existing security restrictions.
Recommendations For Korenix JetPort versions 1.2 and earlier, update to a version later than 1.2 to resolve the issue. For Korenix JetPort 5601v3 versions through 1.2, update to a version later than 1.2 to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-06375
CVE-2024-7395

Affected Products

Korenix Jetport
Korenix Jetport 5601V3