OS Command Injection Vulnerability in Ruckus Wireless Zone Director
CVE-2017-6223
8.8HIGH
Key Information:
- Vendor
- CVE Published:
- 13 October 2017
What is CVE-2017-6223?
The Ruckus Wireless ZoneDirector Controller firmware prior to version 9.13.0.0.232 is vulnerable to OS command injection through its ping functionality. This vulnerability can be exploited by local authenticated users, allowing them to execute arbitrary commands with elevated privileges on the underlying operating system. If not addressed, this could compromise the integrity and security of the network environment managed by the affected firmware.
Affected Version(s)
Zone Director Controller Firmware ZD9.9.x
Zone Director Controller Firmware ZD9.10.x
Zone Director Controller Firmware ZD9.13.0.x
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved