CVE-2020-22656: High severity ruckus wireless r310 firmware vulnerability
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to make the Secure Boot in failed attempts state (rfwd).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-22656?
CVE-2020-22656 is rated as high severity due to its potential for exploitation in Ruckus Wireless products.
How do I fix CVE-2020-22656?
To fix CVE-2020-22656, update the affected Ruckus devices to the latest firmware versions available.
What Ruckus products are affected by CVE-2020-22656?
CVE-2020-22656 affects Ruckus R310, R500, R600, T300, T301n, T301s, SmartCell Gateway 200, SmartZone 100, and SmartZone 300 among others.
When was CVE-2020-22656 disclosed?
CVE-2020-22656 was disclosed in March 2020.
Are there any workarounds for CVE-2020-22656 before patching?
Temporary mitigation strategies may include restricting access to affected devices from untrusted networks until a firmware update can be applied.