CVE-2017-6230

Summary

Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.

Affected Software

VendorProductVersion RangeStatus
Brocade Communications Systems, Inc.Ruckus Networks Solo APs and SZ managed APsSolo AP firmware releases R110.x or before and SZ managed APs firmware release R5.x or beforeaffected

Weaknesses

  • Authenticated command injection in WebUI interface of Solo and managed AP via tftp upgrade option.

ADP Enrichment

CVE Program Container

Additional References

References