CVE-2020-22656

HIGHCVSS 7.5/10EPSS 0.49%

Last modified

CVE-2020-22656 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to make the Secure Boot in failed attempts state (rfwd).. EPSS estimates a 0.49% chance of exploitation in the next 30 days.

Description

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to make the Secure Boot in failed attempts state (rfwd).

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
0.49%

38.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RuckuswirelessR310 Firmware10.5.1.0.199
RuckuswirelessR500 Firmware10.5.1.0.199
RuckuswirelessR600 Firmware10.5.1.0.199
RuckuswirelessT300 Firmware10.5.1.0.199
RuckuswirelessT301n Firmware10.5.1.0.199
RuckuswirelessT301s Firmware10.5.1.0.199
RuckuswirelessScg200 Firmware< 3.6.2.0.795
RuckuswirelessSz-100 Firmware< 3.6.2.0.795
RuckuswirelessSz-300 Firmware< 3.6.2.0.795
RuckuswirelessVsz Firmware< 3.6.2.0.795
RuckuswirelessZonedirector 1100 Firmware9.10.2.0.130
RuckuswirelessZonedirector 1200 Firmware10.2.1.0.218
RuckuswirelessZonedirector 3000 Firmware10.2.1.0.218
RuckuswirelessZonedirector 5000 Firmware10.0.1.0.151

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-22656?
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to make the Secure Boot in failed attempts state (rfwd).
How severe is CVE-2020-22656?
CVE-2020-22656 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.49% probability of exploitation in the next 30 days.
How do I fix CVE-2020-22656?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-22656?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST