PT-2018-8325 · Ruckus Networks · Ruckus Sz+1
Published
2018-02-14
·
Updated
2018-03-16
·
CVE-2017-6230
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ruckus Networks Solo APs versions R110.x or before
Ruckus Networks SZ managed APs versions R5.x or before
Description
The issue concerns an authenticated Root Command Injection in the web-GUI. This could allow authenticated valid users to execute privileged commands on the respective systems.
Recommendations
For Ruckus Networks Solo APs versions R110.x or before, update to a version later than R110.x to resolve the issue.
For Ruckus Networks SZ managed APs versions R5.x or before, update to a version later than R5.x to resolve the issue.
As a temporary workaround, consider restricting access to the web-GUI to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruckus Sz
Ruckus Solo Aps