CVE-2017-6229: Command Injection
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated valid users to execute privileged commands on the respective systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6229?
CVE-2017-6229 has been rated as a high severity vulnerability due to its ability to allow authenticated users to execute arbitrary commands on vulnerable devices.
How do I fix CVE-2017-6229?
To mitigate CVE-2017-6229, upgrade to Ruckus Networks Unleashed AP firmware version 200.6.10.1.x or later and Zone Director firmware version 10.1.0.0.x and later.
Which Ruckus devices are affected by CVE-2017-6229?
CVE-2017-6229 affects Ruckus Networks Unleashed APs and Zone Director devices running specific firmware versions prior to the updated releases.
Can CVE-2017-6229 be exploited remotely?
CVE-2017-6229 requires authenticated access, meaning exploitation is possible only by users who have valid credentials.
What are the potential consequences of CVE-2017-6229 exploitation?
If exploited, CVE-2017-6229 may allow an authenticated user to execute arbitrary commands, potentially compromising the affected system's integrity.