CVE-2017-14021

UnknownEPSS 1.92%

Last modified

CVE-2017-14021 is a vulnerability of currently unknown severity. A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.. EPSS estimates a 1.92% chance of exploitation in the next 30 days.

Description

A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.

Metrics

EPSS Probability
1.92%

77.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
KorenixJetnet5018g Firmware1.4
KorenixJetnet5310g Firmware1.4a
KorenixJetnet5428g-2g-2fx Firmware1.4
KorenixJetnet5628g Firmware1.4
KorenixJetnet5628g-R Firmware1.4
KorenixJetnet5728g-24p Firmware1.4
KorenixJetnet5828g Firmware1.1d
KorenixJetnet6710g Firmware1.1
KorenixJetnet6710g-Hvdc Firmware11e

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-14021?
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC version 1.1e, and JetNet6710G version 1.1. An attacker may gain access to hard-coded certificates and private keys allowing the attacker to perform man-in-the-middle attacks.
How severe is CVE-2017-14021?
Severity scoring for CVE-2017-14021 is pending analysis. The EPSS model estimates a 1.92% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14021?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-14021?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST