12-12-2021 05:51 PM
Hello.
Our customer is running a Ruckus SmartZone (sz-100) controller.
The version of the controller is 5.1.1.0.598.
The customer asked if the SmartZone has the following this security vulnerabilities.
** Vulnerability: [CVE-2021-44228] Apache Log4j2 RCE
Thank you for your valuable answers to the above questions.
12-17-2021 03:02 PM
The KBA is now live in the Support Portal at https://support.ruckuswireless.com/articles/000012025 and it's linked in each of the KSP patches.
The KSP patches and the updated Security Bulletin v1.3 are now linked from the new Log4j - RUCKUS Technical Support Response Center at https://support.ruckuswireless.com/log4j-ruckus-technical-support-response-center
The delay you saw with the KSPs being published earlier and then pulled was because 1) the KBA with KSP instructions didn't synch properly, so we pulled everything down until it was available, and 2) the KSPs had to be regenerated due to technical issues within the compression process (they were downloading as the wrong file types in Chrome).
Everything is now up-to-date and available. As you have feedback, please continue to chime in here---TAC is monitoring the thread actively through @vineet_nejawala and other engineers.
Thank you for your patience and your feedback throughout this process, and happy patching!
Allan.
12-17-2021 05:19 PM
@allan_grohe I'm on macOS Monterey 12.1 and the native built-in archive utility seems to extract the zipped patch/ksp into 3 files (digital_sig.bin, signing_cert.pem and the *.ksp file) and the KSP would not upload (displayed invalid file). I unarchived it with Keka for macOS and it was just one file (the *.ksp) and it uploaded into the controller with no issues. Just a possible FYI for others that may experience this using the macOS built-in archive utility to extract the file.
07-29-2025 07:07 PM
It's 11pm and me and a co-worker were about go nuts when we found your comment. The default decompressor no MacOS does indeed break the file apart into 3. When I tried decompressing it on Windows, it outputted only one KSP file. Thanks!
07-30-2025 05:18 AM
No problem! My post is old but I run into the same issue with the latest Ruckus SZ144 KSP patch 7/2025 as well and latest macOS 15.x, used Keka again. I let Ruckus Support know. They had at least one customer lined up in the queue that sounded like the same issue.
12-17-2021 05:47 PM
@JTakaMT Same thing for me, thanks for dropping the tip! Keka FTW!
