HIGH · 8.8

CVE-2020-8830

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

Vulnerability Description

CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CommscopeRuckus Zoneflex R500 Firmware-
CommscopeRuckus Zoneflex R500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8830?

CVE-2020-8830 is a vulnerability with a CVSS score of 8.8 (HIGH). CSRF in login.asp on Ruckus devices allows an attacker to access the panel, and use SSRF to perform scraping or other analysis via the SUBCA-1 field on the Wireless Admin screen.

How severe is CVE-2020-8830?

CVE-2020-8830 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8830?

Check the references section above for vendor advisories and patch information. Affected products include: Commscope Ruckus Zoneflex R500 Firmware, Commscope Ruckus Zoneflex R500.