12-12-2021 05:51 PM
Hello.
Our customer is running a Ruckus SmartZone (sz-100) controller.
The version of the controller is 5.1.1.0.598.
The customer asked if the SmartZone has the following this security vulnerabilities.
** Vulnerability: [CVE-2021-44228] Apache Log4j2 RCE
Thank you for your valuable answers to the above questions.
12-17-2021 03:02 PM
The KBA is now live in the Support Portal at https://support.ruckuswireless.com/articles/000012025 and it's linked in each of the KSP patches.
The KSP patches and the updated Security Bulletin v1.3 are now linked from the new Log4j - RUCKUS Technical Support Response Center at https://support.ruckuswireless.com/log4j-ruckus-technical-support-response-center
The delay you saw with the KSPs being published earlier and then pulled was because 1) the KBA with KSP instructions didn't synch properly, so we pulled everything down until it was available, and 2) the KSPs had to be regenerated due to technical issues within the compression process (they were downloading as the wrong file types in Chrome).
Everything is now up-to-date and available. As you have feedback, please continue to chime in here---TAC is monitoring the thread actively through @vineet_nejawala and other engineers.
Thank you for your patience and your feedback throughout this process, and happy patching!
Allan.
12-17-2021 05:19 PM
@allan_grohe I'm on macOS Monterey 12.1 and the native built-in archive utility seems to extract the zipped patch/ksp into 3 files (digital_sig.bin, signing_cert.pem and the *.ksp file) and the KSP would not upload (displayed invalid file). I unarchived it with Keka for macOS and it was just one file (the *.ksp) and it uploaded into the controller with no issues. Just a possible FYI for others that may experience this using the macOS built-in archive utility to extract the file.
12-17-2021 05:47 PM
@JTakaMT Same thing for me, thanks for dropping the tip! Keka FTW!
12-17-2021 06:49 PM
@JTakaMT Yes the patch that needs to be uploaded is only .ksp file. Thank you for sharing your inputs that would help others.
Best Regards
vineet
12-18-2021 08:17 AM
@JTakaMT thank you for this!