CVE-2017-6229
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated valid users to execute privileged commands on the respective systems.
Affected (23)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R600 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R310 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless H320 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless H510 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R710 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R720 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless T300 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless T301 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless T300e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless T610 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless T710 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 200.6.10.1.0 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless R510 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.1.0.17 to 10.0.1.0.44 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless Zonedirector 1200 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.1.0.17 to 10.0.1.0.44 |
| Running on/with | Platform Versions |
|---|---|
Ruckuswireless Zonedirector 3000 | All versions |
References (2)
Source: sirt@brocade.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.