CVE-2024-11303
Path Traversal
Record summary
CVE-2024-11303 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.
Description
The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 18, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
JetPort 5601Browse Korenix / JetPort 5601Default status: unaffected, unknown | CVE List, VulnCheck | Through 1.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHKorenix JetPort 5601v3 - Path TraversalCVSS 7.5
The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601- through 1.2.
Impact
Unauthenticated attackers can exploit path traversal to read arbitrary files from the JetPort device server, potentially accessing sensitive configuration files and credentials for connected serial devices.
Remediation
Update Korenix JetPort 5601 to a version newer than 1.2 that properly validates and sanitizes file paths to prevent directory traversal attacks.
Source: ProjectDiscovery