PT-2024-5664 · Korenix · Korenix Jetport 5601V3

S. Dietz

+1

·

Published

2024-04-01

·

Updated

2024-08-07

·

CVE-2024-7396

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Korenix JetPort 5601v3 versions 1.2 and earlier
Description The issue is related to the missing encryption of sensitive data, which allows eavesdropping. This can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations For Korenix JetPort 5601v3 versions 1.2 and earlier, consider implementing encryption for sensitive data transmission to prevent eavesdropping. As a temporary workaround, restrict access to sensitive data until a proper encryption mechanism is in place. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2024-06377
CVE-2024-7396

Affected Products

Korenix Jetport 5601V3