← All Advisories

CVE-2017-20234

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2017-20234

Key Details

CVECVE-2017-20234
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-07-21
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsBelden GarrettCom Magnum 6K and 10K Managed Switches
Classified asCWE-798 (Use of Hard-coded Credentials)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
BeldenGarrettCom Magnum 6K and 10K Managed Switches
SubsystemsGeneral OT
SectorsMultiple

What to Know

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and sensitive switch configuration without valid credentials. (NVD)

What to Do

Monitor Belden's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2017-20234
CVEhttps://www.cve.org/CVERecord?id=CVE-2017-20234