vendor:
Ruckus IoT Controller
by:
korelogic
6.1
CVSS
HIGH
Undocumented Account
798, 912
CWE
Product Name: Ruckus IoT Controller
Affected Version From: 1.7.1.0
Affected Version To: 1.7.1.0
Patch Exists: YES
Related CWE: CVE-2021-33216, CVE-2019-1000018
CPE: a:commscope:ruckus_iot_controller:1.7.1.0
Platforms Tested: Linux
2021
CommScope Ruckus IoT Controller 1.7.1.0 – Undocumented Account
The CommScope Ruckus IoT Controller version 1.7.1.0 and earlier contains an upgrade account that provides undocumented access via Secure Copy (SCP), allowing unauthorized individuals to access the virtual appliance.
Mitigation:
Update to the latest firmware version 1.8.0.0 provided by the vendor to address the vulnerability.