CVE-2023-45992
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
Una vulnerabilidad en la interfaz web del producto RUCKUS Cloudpath en la versión 5.12 build 5538 o anterior podría permitir que un atacante remoto no autenticado ejecute ataques XSS y CSRF persistentes contra un usuario de la interfaz de gestión de administración. Un ataque exitoso, combinado con una determinada actividad administrativa, podría permitir al atacante obtener privilegios completos de administrador en el sistema explotado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-16 CVE Reserved
- 2023-10-19 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-11-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://ruckus.com | Not Applicable | |
https://server.cloudpath | Broken Link | |
https://server.cloudpath/admin/enrollmentData | Broken Link |
URL | Date | SRC |
---|---|---|
https://github.com/harry935/CVE-2023-45992 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.ruckuswireless.com/security_bulletins/322 | 2024-01-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Commscope Search vendor "Commscope" | Ruckus Cloudpath Enrollment System Search vendor "Commscope" for product "Ruckus Cloudpath Enrollment System" | <= 5.12.5538 Search vendor "Commscope" for product "Ruckus Cloudpath Enrollment System" and version " <= 5.12.5538" | - |
Affected
|