CRITICAL
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request
Published Jan 22, 2020
9.8
CRITICALCVSS 3.1
EPSS 4.13%
Description
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.
Affected products
No data.
Configuration 1
AND
- < 200.7.10.202.94
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
AND
OR
- < 9.10.2.0.84
- ≥ 9.12.0 · < 9.12.3.0.136
- ≥ 9.13.0 · < 10.0.1.0.90
- ≥ 10.1.0 · < 10.1.2.0.275
- ≥ 10.2.0 · < 10.2.1.0.147
- ≥ 10.3.0 · < 10.3.1.0.21
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://alephsecurity.com/2020/01/14/ruckus-wireless x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
- https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html x_refsource_MISCThird Party Advisory
- https://www.ruckuswireless.com/security/299/view/txt x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://alephsecurity.com/2020/01/14/ruckus-wireless | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory | |
| https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.html | x_refsource_MISCThird Party Advisory | |
| https://www.ruckuswireless.com/security/299/view/txt | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 22, 2020
Updated Aug 5, 2024
Reserved Dec 17, 2019
Link CVE-2019-19840
CISA Vulnrichment
Updated n/a