Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5376


An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.6, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts integrity (unauthorized modifications), for affected systems. Impacting 84 products from korenix, from korenix, from korenix and 81 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2024, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2024-01-09T10:15:22.823

Last Modified

2025-10-08T10:15:34.333

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-306
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System korenix jetnet_5310g_firmware 2.6 Yes
Hardware korenix jetnet_5310g - No
Operating System korenix jetnet_4508_firmware 2.3 Yes
Hardware korenix jetnet_4508 - No
Operating System korenix jetnet_4508i-w_firmware 1.3 Yes
Hardware korenix jetnet_4508i-w - No
Operating System korenix jetnet_4508-w_firmware 2.3 Yes
Hardware korenix jetnet_4508-w - No
Operating System korenix jetnet_4508if-s_firmware 1.3 Yes
Hardware korenix jetnet_4508if-s - No
Operating System korenix jetnet_4508if-m_firmware 1.3 Yes
Hardware korenix jetnet_4508if-m - No
Operating System korenix jetnet_4508if-sw_firmware 1.3 Yes
Hardware korenix jetnet_4508if-sw - No
Operating System korenix jetnet_4508if-mw_firmware 1.3 Yes
Hardware korenix jetnet_4508if-mw - No
Operating System korenix jetnet_4508f-m_firmware 2.3 Yes
Hardware korenix jetnet_4508f-m - No
Operating System korenix jetnet_4508f-s_firmware 2.3 Yes
Hardware korenix jetnet_4508f-s - No
Operating System korenix jetnet_4508f-mw_firmware 2.3 Yes
Hardware korenix jetnet_4508f-mw - No
Operating System korenix jetnet_4508f-sw_firmware 2.3 Yes
Hardware korenix jetnet_4508f-sw - No
Operating System korenix jetnet_5620g-4c_firmware 1.1 Yes
Hardware korenix jetnet_5620g-4c - No
Operating System korenix jetnet_5612gp-4f_firmware 1.2 Yes
Hardware korenix jetnet_5612gp-4f - No
Operating System korenix jetnet_5612g-4f_firmware 1.2 Yes
Hardware korenix jetnet_5612g-4f - No
Operating System korenix jetnet_5728g-24p-ac-2dc-us_firmware 2.1 Yes
Hardware korenix jetnet_5728g-24p-ac-2dc-us - No
Operating System korenix jetnet_5728g-24p-ac-2dc-eu_firmware 2.1 Yes
Hardware korenix jetnet_5728g-24p-ac-2dc-eu - No
Operating System korenix jetnet_6528gf-2ac-eu_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-2ac-eu - No
Operating System korenix jetnet_6528gf-2ac-us_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-2ac-us - No
Operating System korenix jetnet_6528gf-2dc24_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-2dc24 - No
Operating System korenix jetnet_6528gf-2dc48_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-2dc48 - No
Operating System korenix jetnet_6528gf-ac-eu_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-ac-eu - No
Operating System korenix jetnet_6528gf-ac-us_firmware 1.0 Yes
Hardware korenix jetnet_6528gf-ac-us - No
Operating System korenix jetnet_6628xp-4f-us_firmware 1.1 Yes
Hardware korenix jetnet_6628xp-4f-us - No
Operating System korenix jetnet_6628x-4f-eu_firmware 1.0 Yes
Hardware korenix jetnet_6628x-4f-eu - No
Operating System korenix jetnet_6728g-24p-ac-2dc-us_firmware 1.1 Yes
Hardware korenix jetnet_6728g-24p-ac-2dc-us - No
Operating System korenix jetnet_6728g-24p-ac-2dc-eu_firmware 1.1 Yes
Hardware korenix jetnet_6728g-24p-ac-2dc-eu - No
Operating System korenix jetnet_6828gf-2dc48_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-2dc48 - No
Operating System korenix jetnet_6828gf-2dc24_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-2dc24 - No
Operating System korenix jetnet_6828gf-ac-dc24-us_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-ac-dc24-us - No
Operating System korenix jetnet_6828gf-2ac-us_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-2ac-us - No
Operating System korenix jetnet_6828gf-ac-us_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-ac-us - No
Operating System korenix jetnet_6828gf-2ac-au_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-2ac-au - No
Operating System korenix jetnet_6828gf-ac-dc24-eu_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-ac-dc24-eu - No
Operating System korenix jetnet_6828gf-2ac-eu_firmware 1.0 Yes
Hardware korenix jetnet_6828gf-2ac-eu - No
Operating System korenix jetnet_6910g-m12_hvdc_firmware 1.0 Yes
Hardware korenix jetnet_6910g-m12_hvdc - No
Operating System korenix jetnet_7310g-v2_firmware 1.0 Yes
Hardware korenix jetnet_7310g-v2 - No
Operating System korenix jetnet_7628xp-4f-us_firmware 1.0 Yes
Hardware korenix jetnet_7628xp-4f-us - No
Operating System korenix jetnet_7628xp-4f-us_firmware 1.1 Yes
Hardware korenix jetnet_7628xp-4f-us - No
Operating System korenix jetnet_7628xp-4f-eu_firmware 1.0 Yes
Hardware korenix jetnet_7628xp-4f-eu - No
Operating System korenix jetnet_7628xp-4f-eu_firmware 1.1 Yes
Hardware korenix jetnet_7628xp-4f-eu - No
Operating System korenix jetnet_7628x-4f-us_firmware 1.0 Yes
Hardware korenix jetnet_7628x-4f-us - No
Operating System korenix jetnet_7628x-4f-eu_firmware 1.0 Yes
Hardware korenix jetnet_7628x-4f-eu - No
Operating System korenix jetnet_7714g-m12_hvdc_firmware 1.0 Yes
Hardware korenix jetnet_7714g-m12_hvdc - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For korenix's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.