9.1

CVE-2023-5376

Exploit

An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.

Data is provided by the National Vulnerability Database (NVD)
KorenixJetnet 5310g Firmware Version2.6
   KorenixJetnet 5310g Version-
KorenixJetnet 4508 Firmware Version2.3
   KorenixJetnet 4508 Version-
KorenixJetnet 4508i-w Firmware Version1.3
   KorenixJetnet 4508i-w Version-
KorenixJetnet 4508-w Firmware Version2.3
   KorenixJetnet 4508-w Version-
KorenixJetnet 4508if-s Firmware Version1.3
   KorenixJetnet 4508if-s Version-
KorenixJetnet 4508if-m Firmware Version1.3
   KorenixJetnet 4508if-m Version-
KorenixJetnet 4508if-sw Firmware Version1.3
   KorenixJetnet 4508if-sw Version-
KorenixJetnet 4508if-mw Firmware Version1.3
   KorenixJetnet 4508if-mw Version-
KorenixJetnet 4508f-m Firmware Version2.3
   KorenixJetnet 4508f-m Version-
KorenixJetnet 4508f-s Firmware Version2.3
   KorenixJetnet 4508f-s Version-
KorenixJetnet 4508f-mw Firmware Version2.3
   KorenixJetnet 4508f-mw Version-
KorenixJetnet 4508f-sw Firmware Version2.3
   KorenixJetnet 4508f-sw Version-
KorenixJetnet 5620g-4c Firmware Version1.1
   KorenixJetnet 5620g-4c Version-
KorenixJetnet 5612gp-4f Firmware Version1.2
   KorenixJetnet 5612gp-4f Version-
KorenixJetnet 5612g-4f Firmware Version1.2
   KorenixJetnet 5612g-4f Version-
KorenixJetnet 7310g-v2 Firmware Version1.0
   KorenixJetnet 7310g-v2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.35% 0.561
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
office@cyberdanube.com 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.