CVE-2023-7338 is a remote code execution vulnerability found in the web-based management interface of Ruckus Unleashed systems, exploitable when gateway mode is enabled. This vulnerability, rated 7.5 HIGH, requires authenticated access and high attack complexity, but successful exploitation allows attackers to execute arbitrary code with full impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are public exploit modules available, with only minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ruckus Networks | RUCKUS H350 | unknownCNA affecteddefault affected | |
| Ruckus Networks | RUCKUS H550 | unknownCNA affecteddefault affected | |
| Ruckus Networks | RUCKUS R350 | unknownCNA affecteddefault affected | |
| Ruckus Networks | RUCKUS R550 | unknownCNA affecteddefault affected | |
| Ruckus Networks | RUCKUS R650 | unknownCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.