Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-13917


rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.


Published

2020-07-28T15:15:11.737

Last Modified

2024-11-21T05:02:08.647

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ruckuswireless unleashed_firmware ≤ 200.7.10.102.92 Yes
Hardware ruckuswireless c110 - No
Hardware ruckuswireless e510 - No
Hardware ruckuswireless h320 - No
Hardware ruckuswireless h510 - No
Hardware ruckuswireless m510 - No
Hardware ruckuswireless r310 - No
Hardware ruckuswireless r320 - No
Hardware ruckuswireless r500 - No
Hardware ruckuswireless r510 - No
Hardware ruckuswireless r600 - No
Hardware ruckuswireless r610 - No
Hardware ruckuswireless r710 - No
Hardware ruckuswireless r720 - No
Hardware ruckuswireless r750 - No
Hardware ruckuswireless t300 - No
Hardware ruckuswireless t301n - No
Hardware ruckuswireless t301s - No
Hardware ruckuswireless t310c - No
Hardware ruckuswireless t310d - No
Hardware ruckuswireless t310n - No
Hardware ruckuswireless t310s - No
Hardware ruckuswireless t610 - No
Hardware ruckuswireless t710 - No
Hardware ruckuswireless t710s - No

References