---
cve: "CVE-2023-5347"
severity: "CRITICAL"
cvss: 9.8
epss: "1.3%"
vendor: "Korenix"
kev: false
exploited: false
published: "2024-01-09 10:15:22"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T12:20:21+02:00"
---

# CVE-2023-5347

> 9.8 CRITICAL · 🧪 PoC

## Beschreibung

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.beijerelectronics.com/en/support/Help___online?docId=69947>
- <https://cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetnet-series/>
- <http://seclists.org/fulldisclosure/2024/Jan/11>
- <http://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-5347) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
