← Back to home
ICSA-17-299-01  ·  Published 2017-10-26  ·  View on CISA ICS-CERT ↗

Korenix JetNet

CVSS 9.8 CRITICAL

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit.

Remediations

  • Korenix has produced new firmware that removes the undocumented hard-coded credentials from supported systems. The new firmware is available for download
  • Korenix recommends that affected users use the software support certificate replacement feature to change certificates on affected devices.
  • Users can find customer support links for Korenix at: http://www.korenix-usa.com/contact-us.php

Affected Vendors

Korenix

Affected Products (9)

Korenix · JetNet5728G-24P 1.4
Korenix · JetNet5628G 1.4
Korenix · JetNet5628G-R 1.4
Korenix · JetNet5428G-2G-2FX 1.4
Korenix · JetNet5018G 1.4
Korenix · JetNet6710G-HVDC version 1.1e
Korenix · JetNet5828G 1.1d
Korenix · JetNet6710G 1.1
Korenix · JetNet5310G 1.4a

Affected Sectors

Commercial Facilities, Critical Manufacturing, and Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more