CVE-2017-14021: Critical severity korenix jetnet 5018g firmware vulnerability
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14021?
CVE-2017-14021 is classified as a high severity vulnerability due to the use of hard-coded cryptographic keys.
How do I fix CVE-2017-14021?
To fix CVE-2017-14021, you should upgrade to the latest firmware version provided by Korenix that addresses this vulnerability.
What devices are affected by CVE-2017-14021?
CVE-2017-14021 affects Korenix JetNet devices including models such as JetNet5018G, JetNet5310G, JetNet5428G-2G-2FX, and others running specific firmware versions.
What are the risks of leaving CVE-2017-14021 unpatched?
Leaving CVE-2017-14021 unpatched may lead to unauthorized access and exploitation of the affected devices due to the hard-coded cryptographic key.
When was CVE-2017-14021 reported?
CVE-2017-14021 was reported in 2017 and is part of an ongoing concern regarding hard-coded cryptographic keys in network devices.