Ad

CVE-2017-20234

CRITICAL CVSS 4.0: 9.3 EPSS 0.01%
Updated Apr 07, 2026
GarrettCom
Parameter Value
CVSS 9.3 (CRITICAL)
Type CWE-798 (Hardcoded Credentials)
Vendor GarrettCom
Public PoC No

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and sensitive switch configuration without valid credentials.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0