And even if they work, there should be at LEAST one security nerd there who would have seen the initial announcement and started salivating at figuring out what the root of the vulnerability was. As has been noted, some vendors even broke "embargo" and fixed this more than a month ago (OpenBSD was scolded, Mikrotik apparently was not). If Ruckus doesn't have one of "those guys", god help us.
Here's what the message to management should be, and it should STING:
- Ubiquiti had a fix before you
- Ubiquiti sent an email blast to customers before you informing them of the vulnerability and the fix
- Mikrotik had a fix before you - yes, the Latvians beat you too
- Both companies called out above are seen as barely beyond consumer grade stuff in some circles (and in some Ruckus sales pitches)
- All the enterprise vendors had a fix out before you (but Ubiquiti is the one that should embarrass you)
- Many of your customers read about this elsewhere and are aware that you had the information about this problem in-hand back in August