CVE-2021-4474
Last modified
CVE-2021-4474 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive information including configuration files, credentials, and system data stored on the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Ruckus Wireless | RUCKUS Access Point | All versions |
| Ruckus | RUCKUS Unleashed | All versions |
| Ruckus | SmartZone 100 (SZ-100) (EOL) | All versions |
| Ruckus | SmartZone 100-D (SZ100-D) (EOL) | All versions |
| Ruckus | SmartZone 144 (SZ-144) | All versions |
| Ruckus | SmartZone 144-Dataplane (SZ144-D) | All versions |
| Ruckus | SmartZone 300 (SZ300) (EOL) | All versions |
| Ruckus | ZoneDirector 1200 (EOL) | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2021-4474?
How severe is CVE-2021-4474?
How do I fix CVE-2021-4474?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-44734Embedded web server input sanitization vulnerability in Lexm…9.8
- CVE-2021-44735Embedded web server command injection vulnerability in Lexma…9.8
- CVE-2021-44736The initial admin account setup wizard on Lexmark devices al…9.8
- CVE-2021-44737PJL directory traversal vulnerability in Lexmark devices thr…8.8
- CVE-2021-44738Buffer overflow vulnerability has been identified in Lexmark…9.8
- CVE-2021-44739Acrobat Reader DC ActiveX Control versions 21.007.20099 (and…4.3
- CVE-2021-44740Acrobat Reader DC version 21.007.20099 (and earlier), 20.004…5.5
- CVE-2021-44741Acrobat Reader DC version 21.007.20099 (and earlier), 20.004…5.5
- CVE-2021-44742Acrobat Reader DC version 21.007.20099 (and earlier), 20.004…5.5
- CVE-2021-44743Adobe Bridge version 11.1.2 (and earlier) and version 12.0 (…7.8
- CVE-2021-44746UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0…5.3
- CVE-2021-44747A Denial-of-Service (DoS) vulnerability was discovered in F-…6.5
Are you affected by CVE-2021-4474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
