CVE-2020-21161: XSS
Published Jun 27, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.
Affected Software
4 affected components
Ruckuswireless Zonedirector Firmware=9.8.3.0
Ruckuswireless Zonedirector
All of the following
Ruckuswireless Zonedirector Firmware=9.8.3.0
Ruckuswireless Zonedirector
Event History
Jun 27, 2022
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-21161?
CVE-2020-21161 has a medium severity rating due to the potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2020-21161?
To mitigate CVE-2020-21161, update Ruckus Wireless ZoneDirector to the latest firmware version that addresses the XSS vulnerability.
3
Which versions are affected by CVE-2020-21161?
CVE-2020-21161 specifically affects Ruckus Wireless ZoneDirector firmware version 9.8.3.0.
4
What possible attacks can be executed due to CVE-2020-21161?
Exploitation of CVE-2020-21161 could lead to unauthorized script injection, leading to data theft or session hijacking.
5
Are there any workarounds for CVE-2020-21161 until I can update?
While the best solution is to update, temporarily restricting access to the ZoneDirector interface may reduce exposure to CVE-2020-21161.