CVE-2024-9677

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versionsĀ could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-10-22 02:15

Updated : 2024-12-05 22:11


NVD link : CVE-2024-9677

Mitre link : CVE-2024-9677

CVE.ORG link : CVE-2024-9677


JSON object : View

Products Affected

zyxel

  • usg_flex_200h
  • usg_flex_500h
  • usg_flex_200hp
  • usg_flex_100h
  • uos
  • usg_flex_700h
CWE
CWE-522

Insufficiently Protected Credentials