PT-2018-8324 · Ruckus Networks · Zonedirector+1

Publicado

2018-02-14

·

Atualizado

2018-03-12

·

CVE-2017-6229

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruckus Networks Unleashed AP firmware versions prior to 200.6.10.1.x Ruckus Networks Zone Director firmware versions 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x
Description The issue concerns an authenticated Root Command Injection in the Command Line Interface (CLI) that could allow authenticated valid users to execute privileged commands on the respective systems.
Recommendations For Ruckus Networks Unleashed AP firmware, update to version 200.6.10.1.x or later. For Ruckus Networks Zone Director firmware versions 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x, update to a version later than the specified ones.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6229

Produtos afetados

Ruckus Unleashed
Zonedirector