<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities in ZoneDirector</title>
    <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15382#M3332</link>
    <description>No patch for 9.13?</description>
    <pubDate>Thu, 26 Dec 2019 00:14:20 GMT</pubDate>
    <dc:creator>david_black_594</dc:creator>
    <dc:date>2019-12-26T00:14:20Z</dc:date>
    <item>
      <title>Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15377#M3327</link>
      <description>The &lt;A href="https://www.commscope.com/security-bulletins/" rel="nofollow" target="_blank" title="Link https//supportruckuswirelesscom/security"&gt;RuckusNetworks Support Portal Security&lt;/A&gt; page has been updated with &lt;B&gt;Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code Execution and Other Vulnerabilities&lt;/B&gt;. Security Notice 20191224 is located at &lt;A href="https://www.commscope.com/globalassets/digizuite/62630-20191224-faq-security-advisory-id-20191224-v1-2.pdf" rel="nofollow" target="_blank" title="Link https//supportruckuswirelesscom/security_bulletins/299"&gt;https://support.ruckuswireless.com/security_bulletins/299 &lt;/A&gt;and can be downloaded in PDF and TXT formats. &amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;B&gt;What is the issue?&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;A number of security vulnerabilities are found on the ZoneDirector and Unleashed product lines. Collectively, these vulnerabilities allow an attacker to perform the following actions:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Unauthenticated, remote code executions and unauthorized command line interface (CLI) and shell access&lt;/LI&gt;&lt;LI&gt;Command injections&lt;/LI&gt;&lt;LI&gt;Unauthenticated stack overflow&lt;/LI&gt;&lt;LI&gt;Unauthenticated arbitrary file writing&lt;/LI&gt;&lt;LI&gt;Server-Side Request Forgery (SSRF)&lt;/LI&gt;&lt;/UL&gt;
&lt;B&gt;What action should I take?&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;
Ruckus Networks is releasing the fix for these vulnerabilities through a software update. Because these are CRITICAL issues, all customers are strongly encouraged to apply the fix once available.&lt;BR /&gt;&lt;BR /&gt;
Further details including are available in the full text of Security Notice 20191224 at &lt;A href="https://www.commscope.com/globalassets/digizuite/62630-20191224-faq-security-advisory-id-20191224-v1-2.pdf" rel="nofollow" title="Link: https://support.ruckuswireless.com/security_bulletins/299"&gt;https://support.ruckuswireless.com/security_bulletins/299&lt;/A&gt;. &amp;nbsp;</description>
      <pubDate>Tue, 24 Dec 2019 20:36:59 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15377#M3327</guid>
      <dc:creator>grodog-prod</dc:creator>
      <dc:date>2019-12-24T20:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15378#M3328</link>
      <description>Can the updated version be installed if the end user has controllers with expired support?
&lt;BR /&gt;&lt;BR /&gt;
Which  versions of ZD code will be patched?</description>
      <pubDate>Tue, 24 Dec 2019 23:06:22 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15378#M3328</guid>
      <dc:creator>david_black_594</dc:creator>
      <dc:date>2019-12-24T23:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15379#M3329</link>
      <description>I second this request -- this seems arguably more severe than  KRACK and we got temporary entitlements to patch KRACK back then.</description>
      <pubDate>Wed, 25 Dec 2019 00:04:13 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15379#M3329</guid>
      <dc:creator>john_d</dc:creator>
      <dc:date>2019-12-25T00:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15380#M3330</link>
      <description>Is the attack surface isolated to having access to the management VLAN to talk to the APs / ZD instance, or for Unleashed since it can be managed over the cloud, is there a wider attack surface?
&lt;BR /&gt;&lt;BR /&gt;
Trying to decide if the update justifies bringing my networks down over Christmas!</description>
      <pubDate>Wed, 25 Dec 2019 00:05:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15380#M3330</guid>
      <dc:creator>john_d</dc:creator>
      <dc:date>2019-12-25T00:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15381#M3331</link>
      <description>Hi David &amp;amp; John,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Yes, Ruckus will provide temporary entitlement to allow you to upgrade ZD. Below are the versions has the fix&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR /&gt;ZD Code base&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;9.10.2.0.84&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;9.12.3.0.136&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;10.0.1.0.90&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;10.1.2.0.275&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;10.2.1.0.147&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;10.3.1.0.21&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR /&gt;Unleashed&amp;nbsp;&lt;BR /&gt;200.7.10.202.94&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regards,&lt;BR /&gt;Pradeep&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 25 Dec 2019 01:56:03 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15381#M3331</guid>
      <dc:creator>pradeep_kumar_h</dc:creator>
      <dc:date>2019-12-25T01:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15382#M3332</link>
      <description>No patch for 9.13?</description>
      <pubDate>Thu, 26 Dec 2019 00:14:20 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15382#M3332</guid>
      <dc:creator>david_black_594</dc:creator>
      <dc:date>2019-12-26T00:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15383#M3333</link>
      <description>&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;9.13.x has to Upgrade to 10.0.1 MR1 Refresh
  6&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;RN:&amp;nbsp;&lt;A alt="" href="https://support.ruckuswireless.com/documents/3109-zonedirector-10-0-1-mr1-refresh6-release-notes" name="" rel="nofollow" target="" title="" type="" value=""&gt;https://support.ruckuswireless.com/documents/3109-zonedirector-10-0-1-mr1-refresh6-release-notes&lt;/A&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;Image:&amp;nbsp;&lt;A alt="" href="https://support.ruckuswireless.com/software/2285-zd1200-10-0-1-0-90-mr1-refresh6-software-release" name="" rel="nofollow" target="" title="Link httpssupportruckuswirelesscomsoftware2285-zd1200-10-0-1-0-90-mr1-refresh6-software-release" type="" value=""&gt;https://support.ruckuswireless.com/software/2285-zd1200-10-0-1-0-90-mr1-refresh6-software-release&lt;/A&gt;&lt;/P&gt;
  
 
&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 26 Dec 2019 02:17:25 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15383#M3333</guid>
      <dc:creator>pradeep_kumar_h</dc:creator>
      <dc:date>2019-12-26T02:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15384#M3334</link>
      <description>Hi John,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I am not able to understand "Unleashed since it can be managed over the cloud", please reach out to Ruckus Support to discuss the impact and resolution.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regards,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Pradeep</description>
      <pubDate>Thu, 26 Dec 2019 02:19:17 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15384#M3334</guid>
      <dc:creator>pradeep_kumar_h</dc:creator>
      <dc:date>2019-12-26T02:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Security Notice 20191224 ZoneDirector and Unleashed Unauthenticated Remote Code 
Execution and Other Vulnerabilities</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15385#M3335</link>
      <description>Thanks Pradeep -- the recently published FAQ for Unleashed home users answered my question. Attacking a vulnerable AP requires local network access, which is at least a little bit of a silver lining. I was worried earlier that the attacker could've been anywhere on the internet if they are somehow able to use the same communication mechanism as the Unleashed mobile app to talk to a vulnerable AP over the WAN, but that does not appear to be the case.&lt;BR /&gt;&lt;BR /&gt;Thank you for the quick and coordinated response to this vulnerability!</description>
      <pubDate>Wed, 01 Jan 2020 22:08:16 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/Security-Notice-20191224-ZoneDirector-and-Unleashed/m-p/15385#M3335</guid>
      <dc:creator>john_d</dc:creator>
      <dc:date>2020-01-01T22:08:16Z</dc:date>
    </item>
  </channel>
</rss>

