S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 25, 2024

CVE-2024-11303 Scanner

CVE-2024-11303 Scanner - Path Traversal vulnerability in Korenix JetPort 5601

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-11303
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
JetPort 5601by Korenix
0
jetport_5601by korenix
0
Updated Aug 22, 2026View on NVD →
Detail

Korenix JetPort 5601 is a rugged industrial Ethernet device designed for industrial IoT connectivity. It is primarily used in industrial control systems, surveillance, and network communications. The device facilitates serial-to-Ethernet communication, ensuring robust performance in harsh environments. It is popular in sectors such as manufacturing, transportation, and automation. JetPort 5601 devices are designed for reliability, offering features like secure remote management and flexible networking options. However, certain versions of JetPort 5601 are affected by a serious vulnerability that can be exploited remotely.

The vulnerability allows attackers to perform a path traversal attack on affected Korenix JetPort 5601 devices. Path Traversal occurs when the software does not properly sanitize user inputs, allowing malicious users to navigate outside the intended directory structure. By exploiting this flaw, an attacker can access sensitive files and data, such as system files. This issue has been identified as a severe security risk and can lead to unauthorized access to the underlying system. It affects JetPort 5601 devices up to version 1.2. The vulnerability can be triggered by sending specially crafted requests to the device.

This vulnerability is triggered by a specially crafted HTTP GET request that manipulates the file path in a way that allows the attacker to access restricted files. The attacker can use encoded characters like '%2e%2e' to traverse directories and reach critical files such as '/etc/passwd'. The vulnerability is exposed through a web interface, making it accessible remotely. Once exploited, attackers can view or manipulate sensitive system files. This flaw is due to improper input validation on the server-side and is commonly found in web applications that allow file path manipulation.

If exploited, this vulnerability can lead to the disclosure of sensitive system files, such as password files. An attacker could gain unauthorized access to system-level files and potentially escalate privileges on the affected system. This could allow for further exploitation, including the installation of backdoors or the compromise of network integrity. Additionally, the ability to manipulate or steal sensitive data could have significant security and privacy implications. Attackers could also use this vulnerability to map the internal file structure, aiding in future attacks.

REFERENCES

Solution Advice
  • Upgrade to the latest version of Korenix JetPort 5601 where this vulnerability is patched.
  • Implement input validation mechanisms to prevent directory traversal attacks.
  • Limit access to sensitive files and ensure that only authorized users can access critical system files.
  • Regularly monitor and audit logs for suspicious activities related to path traversal attempts.
  • Deploy a Web Application Firewall (WAF) to filter out malicious requests targeting the device.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.