RUCKUS ICX Switches Impacted by CVE?2018?10933 (libssh Vulnerability)
Summary
This Knowledge Base Article addresses customer concerns regarding CVE?2018?10933, a vulnerability associated with the libssh server implementation. Based on validation by the RUCKUS Security Team, RUCKUS ICX switches are not impacted, as ICX does not use the libssh library for SSH server functionality.Question
Are RUCKUS ICX switches vulnerable to CVE?2018?10933?
Customer Environment
- RUCKUS ICX switches deployed in enterprise or service?provider networks - ICX platforms using SSH for device management - All FastIron software versions released up to and including October 30, 2018Symptoms
Root Cause
CVE?2018?10933 affects applications that use the libssh library to implement an SSH server, potentially allowing unauthorized access. RUCKUS ICX switches do not use the libssh library for SSH server implementation. Therefore, the vulnerability does not apply to ICX products. The issue only affects libssh server?side implementations. SSH client functionality is not impacted, and the vulnerability does not affect OpenSSH or libssh2.Troubleshooting Steps
Workaround
No workaround is required. RUCKUS ICX switches are not affected by CVE?2018?10933.
Resolution
The RUCKUS Security Team has confirmed that all RUCKUS ICX products are not vulnerable to CVE?2018?10933 for all software versions released up to October 30, 2018. ICX does not rely on the libssh library for SSH server functionality.
Customers can reference the official RUCKUS Security Bulletin below for additional confirmation:
- RUCKUS Security Bulletin
https://support.ruckuswireless.com/security_bulletins/290
External References
Article Number:
000008536
Updated:
April 16, 2026 01:14 PM (about 1 month ago)
Tags:
Security, Ruckus ICX Switches
Votes:
0
This article is:
helpful
not helpful