The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versionsĀ could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2024-10-22 02:15
Updated : 2024-12-05 22:11
NVD link : CVE-2024-9677
Mitre link : CVE-2024-9677
CVE.ORG link : CVE-2024-9677
JSON object : View
Products Affected
zyxel
- usg_flex_200h
- usg_flex_500h
- usg_flex_200hp
- usg_flex_100h
- uos
- usg_flex_700h
CWE
CWE-522
Insufficiently Protected Credentials
