CVE-2020-8033: XSS
Published May 5, 2020
·Updated
Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field.
Affected Software
2 affected components
CommScope Ruckus Zoneflex R500 Firmware=3.4.2.0.384
CommScope Ruckus Zoneflex R500
Event History
May 5, 2020
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-8033.
2
What is the severity of CVE-2020-8033?
The severity of CVE-2020-8033 is medium with a severity value of 6.1.
3
How does CVE-2020-8033 impact Ruckus R500 3.4.2.0.384 devices?
CVE-2020-8033 allows XSS (Cross-Site Scripting) attacks via the index.asp Device Name field on Ruckus R500 3.4.2.0.384 devices.
4
How can I fix CVE-2020-8033 on my Ruckus R500 3.4.2.0.384 device?
To fix CVE-2020-8033, you should update your Ruckus R500 device firmware to a version that is not vulnerable, when available. Additionally, you can apply web application firewall (WAF) rules to mitigate the XSS attack.
5
Where can I find more information about CVE-2020-8033?
More information about CVE-2020-8033 can be found at the following reference link: https://gist.github.com/CyberSecurityUP/26c5b032897630fe8407da4a8ef216d4