CVE-2017-14021

A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-17-299-01 US Government Resource Third Party Advisory
http://www.securityfocus.com/bid/101598 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:korenix:jetnet5018g_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5018g:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:korenix:jetnet5310g_firmware:1.4a:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5310g:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:korenix:jetnet5428g-2g-2fx_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5428g-2g-2fx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:korenix:jetnet5628g_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5628g:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:korenix:jetnet5628g-r_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5628g-r:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:korenix:jetnet5728g-24p_firmware:1.4:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5728g-24p:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:korenix:jetnet5828g_firmware:1.1d:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet5828g:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:korenix:jetnet6710g_firmware:1.1:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet6710g:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:korenix:jetnet6710g-hvdc_firmware:11e:*:*:*:*:*:*:*
cpe:2.3:h:korenix:jetnet6710g-hvdc:-:*:*:*:*:*:*:*

Information

Published : 2017-10-31 19:29

Updated : 2019-10-09 16:23


NVD link : CVE-2017-14021

Mitre link : CVE-2017-14021


JSON object : View

CWE
CWE-798

Use of Hard-coded Credentials

Advertisement

dedicated server usa

Products Affected

korenix

  • jetnet5018g_firmware
  • jetnet5828g
  • jetnet5628g-r_firmware
  • jetnet5628g-r
  • jetnet5828g_firmware
  • jetnet5728g-24p
  • jetnet6710g
  • jetnet6710g-hvdc
  • jetnet5428g-2g-2fx_firmware
  • jetnet5428g-2g-2fx
  • jetnet5628g_firmware
  • jetnet6710g_firmware
  • jetnet5310g
  • jetnet5628g
  • jetnet5018g
  • jetnet6710g-hvdc_firmware
  • jetnet5310g_firmware
  • jetnet5728g-24p_firmware