Record summary

CVE-2024-11303 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.

Description

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 11, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 18, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE List, VulnCheckThrough 1.2affected

Nuclei templates

1
ProjectDiscoveryHIGHKorenix JetPort 5601v3 - Path TraversalCVSS 7.5

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601- through 1.2.

Impact

Unauthenticated attackers can exploit path traversal to read arbitrary files from the JetPort device server, potentially accessing sensitive configuration files and credentials for connected serial devices.

Remediation

Update Korenix JetPort 5601 to a version newer than 1.2 that properly validates and sanitizes file paths to prevent directory traversal attacks.

WeaknessesCWE-22
Authorsgeeknik
Template tagsseclistscvecve2024korenixlfivulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Source: ProjectDiscovery

References

3