CVE-2023-45992: XSS
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
Other sources
Cross Site Scripting vulnerability in Ruckus Wireless (CommScope) Ruckus CloudPath v.5.12.54414 allows a remote attacker to escalate privileges via a crafted script to the macaddress parameter in the onboarding portal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ROCKUS Cloudpath (RUCKUS CloudPath product)to a version that resolves this vulnerability.Fixed in 5.12 build 5538 - Upgrade
Upgrade
Ruckus Wireless (CommScope) Ruckus CloudPathto a version that resolves this vulnerability.Fixed in v.5.12.54414 - Upgrade
Upgrade
Ruckus CloudPath onboarding portal (macaddress parameter)to a version that resolves this vulnerability.Fixed in v.5.12.54414
Event History
Frequently Asked Questions
What is CVE-2023-45992?
CVE-2023-45992 is a Cross Site Scripting (XSS) vulnerability found in Ruckus Wireless (CommScope) Ruckus CloudPath version 5.12 build 54414 and earlier.
How severe is CVE-2023-45992?
CVE-2023-45992 has a severity rating of 9.6 (Critical).
What is the affected software version of CVE-2023-45992?
The affected software version of CVE-2023-45992 is Ruckus Wireless (CommScope) Ruckus CloudPath version 5.12 build 54414 and earlier.
How can an attacker exploit CVE-2023-45992?
An attacker can exploit CVE-2023-45992 by performing persistent Cross Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks against a user of the admin management interface.
Are there any references for CVE-2023-45992?
Yes, you can find references for CVE-2023-45992 at the following URLs: http://ruckus.com, https://github.com/harry935/CVE-2023-45992, and https://server.cloudpath/.