Vulnerability CVE-2017-6223


Published: 2017-10-13

Description:
Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerabilities in the ping functionality that could allow local authenticated users to execute arbitrary privileged commands on the underlying operating system.

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Ruckus -> Zonedirector firmware 

 References:
https://ruckus-www.s3.amazonaws.com/pdf/security/faq-security-advisory-id-092917.txt

Copyright 2024, cxsecurity.com

 

Back to Top