CVE-2017-20234 is a critical authentication bypass vulnerability impacting GarrettCom Magnum 6K and 10K managed switches. It allows unauthenticated attackers to gain unauthorized administrative access by exploiting a hardcoded string in the authentication mechanism. Rated with a CVSS score of 9.8, this vulnerability has a network attack vector and low attack complexity, enabling full compromise of switch configurations and sensitive data without valid credentials. While severe, there is currently no public exploit code available (e.g., Metasploit, Nuclei, ExploitDB), nor is there evidence of active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Belden | GarrettCom Magnum 6K And 10K Managed Switches | >= 0, <= 4.6.0, >= 0, <= 4.7.6CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.