7.5
CVSSv2

CVE-2021-33221

Published: 07/07/2021 Updated: 09/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in CommScope Ruckus IoT Controller 1.7.1.0 and previous versions. There are Unauthenticated API Endpoints.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

commscope ruckus iot controller

Vendor Advisories

Check Point Reference: CPAI-2021-2139 Date Published: 21 Mar 2024 Severity: Critical ...

Exploits

Three API endpoints for the IoT Controller are accessible without authentication Two of the endpoints result in information leakage and consumption of computing/storage resources The third API endpoint that does not require authentication allows for a factory reset of the IoT Controller ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> KL-001-2021-001: CommScope Ruckus IoT Controller Unauthenticated API Endpoints <!--X-Subject-Header-End--> <!--X-Head- ...