PT-2020-19930 · Ruckus · Ruckus R500

Published

2020-05-05

·

Updated

2020-05-07

·

CVE-2020-8033

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ruckus R500 version 3.4.2.0.384
Description The issue allows for cross-site scripting (XSS) attacks via the Device Name field in the index.asp page.
Recommendations For Ruckus R500 version 3.4.2.0.384, avoid using the Device Name field in the index.asp page until a fix is available. As a temporary workaround, consider restricting access to the index.asp page to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8033

Affected Products

Ruckus R500