Vulnerability Description
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ruckuswireless | Unleashed | < 200.7.10.202.94 |
| Ruckuswireless | C110 | - |
| Ruckuswireless | E510 | - |
| Ruckuswireless | H320 | - |
| Ruckuswireless | H510 | - |
| Ruckuswireless | M510 | - |
| Ruckuswireless | R310 | - |
| Ruckuswireless | R320 | - |
| Ruckuswireless | R510 | - |
| Ruckuswireless | R610 | - |
| Ruckuswireless | R710 | - |
| Ruckuswireless | R720 | - |
| Ruckuswireless | T310 | - |
| Ruckuswireless | T610 | - |
| Ruckuswireless | T710 | - |
| Ruckuswireless | Zonedirector 1200 Firmware | < 9.10.2.0.84 |
| Ruckuswireless | Zonedirector 1200 | - |
Related Weaknesses (CWE)
References
- https://alephsecurity.com/2020/01/14/ruckus-wirelessExploitTechnical DescriptionThird Party Advisory
- https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.htmlThird Party Advisory
- https://www.ruckuswireless.com/security/299/view/txtVendor Advisory
- https://alephsecurity.com/2020/01/14/ruckus-wirelessExploitTechnical DescriptionThird Party Advisory
- https://fahrplan.events.ccc.de/congress/2019/Fahrplan/events/10816.htmlThird Party Advisory
- https://www.ruckuswireless.com/security/299/view/txtVendor Advisory
FAQ
What is CVE-2019-19834?
CVE-2019-19834 is a vulnerability with a CVSS score of 7.2 (HIGH). Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parame...
How severe is CVE-2019-19834?
CVE-2019-19834 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19834?
Check the references section above for vendor advisories and patch information. Affected products include: Ruckuswireless Unleashed, Ruckuswireless C110, Ruckuswireless E510, Ruckuswireless H320, Ruckuswireless H510.