CVE-2017-20234 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 3, 2026
GarrettCom Magnum - Authentication Bypass
Published: April 3, 2026Updated: April 3, 2026Remote Exploitable
Overview
GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass caused by a hardcoded string in the authentication mechanism, letting unauthenticated attackers access administrative functions and sensitive configurations.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can access administrative functions and sensitive configurations, leading to full control over the switch.
Mitigation
Update to the latest version with the authentication bypass fix.
References
Related Resources
Details
- CVE ID
- CVE-2017-20234
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- broken_authentication
- Status
- new
CWE
- CWE-798
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H