CVE-2021-36630
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attacks via crafted request.
Vulnerabilidad de amplificación de reflexión DDOS en el módulo eAut del controlador Ruckus Wireless SmartZone que permite a atacantes remotos realizar ataques DOS a través de una solicitud manipulada.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-07-12 CVE Reserved
- 2023-01-18 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-09-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://ruckus.com | Not Applicable | |
http://smartzone-100.com | Broken Link |
URL | Date | SRC |
---|---|---|
https://github.com/lixiang957/CVE-2021-36630 | 2024-08-04 | |
https://anquan.baidu.com/article/1434 | 2024-08-04 | |
https://www.freebuf.com/articles/web/260338.html | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ruckuswireless Search vendor "Ruckuswireless" | Sz-300 Firmware Search vendor "Ruckuswireless" for product "Sz-300 Firmware" | <= 3.6.2 Search vendor "Ruckuswireless" for product "Sz-300 Firmware" and version " <= 3.6.2" | - |
Affected
| in | Ruckuswireless Search vendor "Ruckuswireless" | Sz-300 Search vendor "Ruckuswireless" for product "Sz-300" | - | - |
Safe
|
Ruckuswireless Search vendor "Ruckuswireless" | Sz-144 Firmware Search vendor "Ruckuswireless" for product "Sz-144 Firmware" | <= 3.6.2 Search vendor "Ruckuswireless" for product "Sz-144 Firmware" and version " <= 3.6.2" | - |
Affected
| in | Ruckuswireless Search vendor "Ruckuswireless" | Sz-144 Search vendor "Ruckuswireless" for product "Sz-144" | - | - |
Safe
|
Ruckuswireless Search vendor "Ruckuswireless" | Sz-100 Firmware Search vendor "Ruckuswireless" for product "Sz-100 Firmware" | <= 3.6.2 Search vendor "Ruckuswireless" for product "Sz-100 Firmware" and version " <= 3.6.2" | - |
Affected
| in | Ruckuswireless Search vendor "Ruckuswireless" | Sz-100 Search vendor "Ruckuswireless" for product "Sz-100" | - | - |
Safe
|
Ruckuswireless Search vendor "Ruckuswireless" | Vsz Firmware Search vendor "Ruckuswireless" for product "Vsz Firmware" | <= 3.6.2 Search vendor "Ruckuswireless" for product "Vsz Firmware" and version " <= 3.6.2" | - |
Affected
| in | Ruckuswireless Search vendor "Ruckuswireless" | Vsz Search vendor "Ruckuswireless" for product "Vsz" | - | - |
Safe
|