HIGH
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI
Published Jan 23, 2020
7.5
HIGHCVSS 3.1
EPSS 1.78%
Description
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
Affected products
No data.
Configuration 1
AND
- < 200.7.10.202.94
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
AND
OR
- < 9.10.2.0.84
- ≥ 9.12.0 · < 9.12.3.0.136
- ≥ 9.13.0 · < 10.0.1.0.90
- ≥ 10.1.0 · < 10.1.2.0.275
- ≥ 10.2.0 · < 10.2.1.0.147
- ≥ 10.3.0 · < 10.3.1.0.21
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://alephsecurity.com/2020/01/14/ruckus-wireless x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html x_refsource_MISCThird Party Advisory
- https://www.ruckuswireless.com/security/299/view/txt x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://alephsecurity.com/2020/01/14/ruckus-wireless | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html | x_refsource_MISCThird Party Advisory | |
| https://www.ruckuswireless.com/security/299/view/txt | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 23, 2020
Updated Aug 5, 2024
Reserved Dec 17, 2019
Link CVE-2019-19835
CISA Vulnrichment
Updated n/a