An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.
Workaround:
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://www.beijerelectronics.com/en/support/Help___online?docId=69947 | vendor advisory |
https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/ | third party advisory exploit |
http://seclists.org/fulldisclosure/2024/Jan/11 | mailing list third party advisory exploit |
http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html | third party advisory vdb entry exploit |