CVE-2020-22660: High severity ruckus wireless r310 firmware vulnerability
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to force bypass Secure Boot failed attempts and run temporarily the previous Backup image.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-22660?
CVE-2020-22660 is rated as a medium severity vulnerability due to its potential to allow unauthorized access to affected Ruckus devices.
How do I fix CVE-2020-22660?
To fix CVE-2020-22660, upgrade the affected Ruckus firmware to a version that includes the security patches addressing this vulnerability.
Which Ruckus products are affected by CVE-2020-22660?
The affected products include R310, R500, R600, T300, T301n, T301s, SCG200, SZ-100, and SZ-300 with specific firmware versions.
Is there a workaround for CVE-2020-22660?
No official workarounds have been provided for CVE-2020-22660, so upgrading the firmware is recommended.
What kind of attack can CVE-2020-22660 enable?
CVE-2020-22660 could potentially allow an attacker to gain unauthorized access and compromise the affected devices' security.