Vulnerability CVE-2024-9677


Published: 2024-10-22

Description:
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versionsĀ could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.

Type:

CWE-522

(Insufficiently Protected Credentials)

 References:
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-insufficiently-protected-credentials-vulnerability-in-firewalls-10-22-2024

Copyright 2024, cxsecurity.com

 

Back to Top