// For flags

CVE-2017-14021

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.

Se ha descubierto un problema de uso de clave criptográfica embebida en Korenix JetNet JetNet5018G versión 1.4, JetNet5310G versión 1.4a, JetNet5428G-2G-2FX versión 1.4, JetNet5628G-R versión 1.4, JetNet5628G versión 1.4, JetNet5728G-24P versión 1.4, JetNet5828G versión 1.1d, JetNet6710G-HVDC versión 1.1e y JetNet6710G versión 1.1. Un atacante puede conseguir acceder a certificados y claves privadas embebidos, lo que le permite realizar ataques Man-in-the-Middle (MitM).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-08-30 CVE Reserved
  • 2017-11-01 CVE Published
  • 2023-03-24 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-321: Use of Hard-coded Cryptographic Key
  • CWE-798: Use of Hard-coded Credentials
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Korenix
Search vendor "Korenix"
Jetnet5018g Firmware
Search vendor "Korenix" for product "Jetnet5018g Firmware"
1.4
Search vendor "Korenix" for product "Jetnet5018g Firmware" and version "1.4"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5018g
Search vendor "Korenix" for product "Jetnet 5018g"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5310g Firmware
Search vendor "Korenix" for product "Jetnet5310g Firmware"
1.4a
Search vendor "Korenix" for product "Jetnet5310g Firmware" and version "1.4a"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5310g
Search vendor "Korenix" for product "Jetnet 5310g"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5428g-2g-2fx Firmware
Search vendor "Korenix" for product "Jetnet5428g-2g-2fx Firmware"
1.4
Search vendor "Korenix" for product "Jetnet5428g-2g-2fx Firmware" and version "1.4"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5428g-2g-2fx
Search vendor "Korenix" for product "Jetnet 5428g-2g-2fx"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5628g Firmware
Search vendor "Korenix" for product "Jetnet5628g Firmware"
1.4
Search vendor "Korenix" for product "Jetnet5628g Firmware" and version "1.4"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5628g
Search vendor "Korenix" for product "Jetnet 5628g"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5628g-r Firmware
Search vendor "Korenix" for product "Jetnet5628g-r Firmware"
1.4
Search vendor "Korenix" for product "Jetnet5628g-r Firmware" and version "1.4"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5628g-r
Search vendor "Korenix" for product "Jetnet 5628g-r"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5728g-24p Firmware
Search vendor "Korenix" for product "Jetnet5728g-24p Firmware"
1.4
Search vendor "Korenix" for product "Jetnet5728g-24p Firmware" and version "1.4"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5728g-24p
Search vendor "Korenix" for product "Jetnet 5728g-24p"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet5828g Firmware
Search vendor "Korenix" for product "Jetnet5828g Firmware"
1.1d
Search vendor "Korenix" for product "Jetnet5828g Firmware" and version "1.1d"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 5828g
Search vendor "Korenix" for product "Jetnet 5828g"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet6710g Firmware
Search vendor "Korenix" for product "Jetnet6710g Firmware"
1.1
Search vendor "Korenix" for product "Jetnet6710g Firmware" and version "1.1"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 6710g
Search vendor "Korenix" for product "Jetnet 6710g"
--
Safe
Korenix
Search vendor "Korenix"
Jetnet6710g-hvdc Firmware
Search vendor "Korenix" for product "Jetnet6710g-hvdc Firmware"
11e
Search vendor "Korenix" for product "Jetnet6710g-hvdc Firmware" and version "11e"
-
Affected
in Korenix
Search vendor "Korenix"
Jetnet 6710g-hvdc
Search vendor "Korenix" for product "Jetnet 6710g-hvdc"
--
Safe