CVE-2017-6230
Last modified
CVE-2017-6230 is a vulnerability of currently unknown severity. Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.. EPSS estimates a 2.27% chance of exploitation in the next 30 days.
Description
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ruckuswireless | Solo Access Point Firmware | <= r110.0 |
| Ruckuswireless | Smartzone Managed Access Point Firmware | <= r5.0 |
References
- https://ruckus-www.s3.amazonaws.com/pdf/security/faq-security-advisory-id-20180202-v1.0.txtMitigation, Vendor Advisory
- https://ruckus-www.s3.amazonaws.com/pdf/security/faq-security-advisory-id-20180202-v1.0.txtMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6230?
How severe is CVE-2017-6230?
How do I fix CVE-2017-6230?
Are you affected by CVE-2017-6230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
