Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-53mp-gj4v-gr9v

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command !v54! via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command !v54! via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

EPSS

Процентиль: 19%
0.0006
Низкий

8.8 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 8.8
nvd
7 месяцев назад

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

EPSS

Процентиль: 19%
0.0006
Низкий

8.8 High

CVSS3

Дефекты

CWE-250