CVE-2023-23294
Published on: Not Yet Published
Last Modified on: 03/06/2023 06:42:00 PM UTC
Certain versions of Jetwave 2111 from Korenix contain the following vulnerability:
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
- CVE-2023-23294 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[EN] Multiple Vulnerabilities in Korenix JetWave Series - CyberDanube | cyberdanube.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Korenix | Jetwave 2111 | - | All | All | All |
Hardware
| Korenix | Jetwave 2111l | - | All | All | All |
Operating System | Korenix | Jetwave 2111l Firmware | All | All | All | All |
Operating System | Korenix | Jetwave 2111 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 2114 | - | All | All | All |
Operating System | Korenix | Jetwave 2114 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 2211c | - | All | All | All |
Operating System | Korenix | Jetwave 2211c Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 2212g | - | All | All | All |
Operating System | Korenix | Jetwave 2212g Firmware | 1.3.t | All | All | All |
Hardware
| Korenix | Jetwave 2212s | - | All | All | All |
Operating System | Korenix | Jetwave 2212s Firmware | 1.3.0 | All | All | All |
Hardware
| Korenix | Jetwave 2212x | - | All | All | All |
Operating System | Korenix | Jetwave 2212x Firmware | 1.3.0 | All | All | All |
Hardware
| Korenix | Jetwave 2411 | - | All | All | All |
Hardware
| Korenix | Jetwave 2411l | - | All | All | All |
Operating System | Korenix | Jetwave 2411l Firmware | All | All | All | All |
Operating System | Korenix | Jetwave 2411 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 2414 | - | All | All | All |
Operating System | Korenix | Jetwave 2414 Firmware | All | All | All | All |
Operating System | Korenix | Jetwave 2424 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 2460 | - | All | All | All |
Operating System | Korenix | Jetwave 2460 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 3220 V3 | - | All | All | All |
Operating System | Korenix | Jetwave 3220 V3 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 3420 V3 | - | All | All | All |
Operating System | Korenix | Jetwave 3420 V3 Firmware | All | All | All | All |
Hardware
| Korenix | Jetwave 4221hp-e | - | All | All | All |
Operating System | Korenix | Jetwave 4221hp-e Firmware | All | All | All | All |
- cpe:2.3:h:korenix:jetwave_2111:-:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2111l:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2111l_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2111_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2114:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2114_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2211c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2211c_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2212g:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2212g_firmware:1.3.t:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2212s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2212s_firmware:1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2212x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2212x_firmware:1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2411:-:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2411l:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2411l_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2411_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2414:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2414_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2424_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_2460:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_2460_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_3220_v3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_3220_v3__firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_3420_v3:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_3420_v3__firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:korenix:jetwave_4221hp-e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:korenix:jetwave_4221hp-e__firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-23294 : Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injectio… twitter.com/i/web/status/1… | 2023-02-23 23:03:38 |
![]() |
Potentially Critical CVE Detected! CVE-2023-23294 Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 a… twitter.com/i/web/status/1… | 2023-02-23 23:56:01 |
![]() |
CVE-2023-23294 | 2023-02-23 23:38:46 |