CVE-2023-7338

HIGHCVSS 7.7/10EPSS 0.52%

Last modified

CVE-2023-7338 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management interface to achieve arbitrary code execution on affected systems.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.

Description

Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management interface to achieve arbitrary code execution on affected systems.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS 4.0
7.7/10

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.52%

40.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Ruckus NetworksRUCKUS H350unknown
Ruckus NetworksRUCKUS H550unknown
Ruckus NetworksRUCKUS R350unknown
Ruckus NetworksRUCKUS R550unknown
Ruckus NetworksRUCKUS R650unknown
Ruckus NetworksRUCKUS R750unknown
Ruckus NetworksRUCKUS R850unknown
Ruckus NetworksRUCKUS T350cunknown
Ruckus NetworksRUCKUS T350dunknown
Ruckus NetworksRUCKUS T350seunknown
Ruckus NetworksRUCKUS T750unknown
Ruckus NetworksRUCKUS T750SEunknown
Ruckus NetworksRUCKUS Unleashedunknown
Ruckus NetworksRuckus C110unknown
Ruckus NetworksRuckus E510unknown
Ruckus NetworksRuckus H320unknown
Ruckus NetworksRuckus H510unknown
Ruckus NetworksRuckus M510-JPunknown
Ruckus NetworksRuckus R320unknown
Ruckus NetworksRuckus R510unknown
Ruckus NetworksRuckus R610unknown
Ruckus NetworksRuckus R710unknown
Ruckus NetworksRuckus R720unknown
Ruckus NetworksRuckus T310cunknown
Ruckus NetworksRuckus T310dunknown
Ruckus NetworksRuckus T310nunknown
Ruckus NetworksRuckus T310sunknown
Ruckus NetworksRuckus T610unknown
Ruckus NetworksRuckus T710unknown
Ruckus NetworksRuckus T710sunknown

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2023-7338?
Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authenticated remote attackers to execute arbitrary code on the system when gateway mode is enabled. Attackers can exploit this vulnerability by sending specially crafted requests through the management interface to achieve arbitrary code execution on affected systems.
How severe is CVE-2023-7338?
CVE-2023-7338 has a CVSS score of 7.7/10 (HIGH severity). The EPSS model estimates a 0.52% probability of exploitation in the next 30 days.
How do I fix CVE-2023-7338?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-7338?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST