Critical severity9.6NVD Advisory· Published Oct 19, 2023· Updated Jul 9, 2026
CVE-2023-45992
CVE-2023-45992
Description
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- RUCKUS/Cloudpathdescription
- cpe:2.3:a:commscope:ruckus_cloudpath_enrollment_system:*:*:*:*:*:*:*:*Range: <=5.12.5538
Patches
Vulnerability mechanics
References
3- support.ruckuswireless.com/security_bulletins/322nvdVendor Advisory
- server.cloudpathnvdBroken Link
- server.cloudpath/admin/enrollmentData/nvdBroken Link
News mentions
0No linked articles in our index yet.