CVE-2017-20234 - CVE House
Back to Database
Status published Critical CVE-2017-20234

GarrettCom Magnum 6K and 10K Authentication Bypass via Hardcoded String

Vulnerability Description

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers can bypass login controls to access administrative functions and sensitive switch configuration without valid credentials.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-20234

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

GarrettCom Magnum 6K and 10K Managed Switches
Vulnerable Versions:
0, 4.7.7

Timeline

Official Publish: April 3rd, 2026
Last Modified: April 6th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)