PT-2018-8325 · Ruckus Networks · Ruckus Sz+1

Publicado

2018-02-14

·

Atualizado

2018-03-16

·

CVE-2017-6230

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ruckus Networks Solo APs versions R110.x or before Ruckus Networks SZ managed APs versions R5.x or before
Description The issue concerns an authenticated Root Command Injection in the web-GUI. This could allow authenticated valid users to execute privileged commands on the respective systems.
Recommendations For Ruckus Networks Solo APs versions R110.x or before, update to a version later than R110.x to resolve the issue. For Ruckus Networks SZ managed APs versions R5.x or before, update to a version later than R5.x to resolve the issue. As a temporary workaround, consider restricting access to the web-GUI to minimize the risk of exploitation.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6230

Produtos afetados

Ruckus Sz
Ruckus Solo Aps