CVE-2017-6224
Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 release) and Ruckus Wireless Unleashed AP Firmware releases 200.0.x, 200.1.x, 200.2.x, 200.3.x, 200.4.x. contain OS Command Injection vulnerabilities that could allow local authenticated users to execute arbitrary privileged commands on the underlying operating system by appending those commands in the Common Name field in the Certificate Generation Request.
Published:Oct 13, 2017
Last Modified:Apr 20, 2025
EPS:Oct 13, 2017
EPSS Score:0.00749
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Ruckuswireless
Product
Unleashed
Ruckuswireless
Unleashed
Vendor
Ruckuswireless
Product
Unleashed Firmware
Ruckuswireless
Unleashed Firmware
Vendor
Ruckuswireless
Product
Zonedirector
Ruckuswireless
Zonedirector
Vendor
Ruckuswireless
Product
Zonedirector Firmware
Ruckuswireless
Zonedirector Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
