CVE Published: 14/02/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: brocade |
Vendor: Brocade Communications Systems, Inc. |
Product: Ruckus Networks Solo APs and SZ managed APs Status : PUBLISHED
CVE-2017-6230 Description
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
CWE-ID: CWE Name: Authenticated command injection in WebUI interface of Solo and managed AP via tftp upgrade option. Source: Brocade Communications Systems, Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)