CVE Feed

    Dashboard / CVE / CVE-2023-45992

    CVE-2023-45992

    A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

    Published:Oct 19, 2023
    Last Modified:Nov 21, 2024
    EPS:Oct 19, 2023
    EPSS Score:0.00551
    CVSS Score:9.6

    Affected Products

    Vendor
    Commscope
    Product
    Ruckus Cloudpath Enrollment System

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High