CVE-2024-9677

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*

History

05 Dec 2024, 22:11

Type Values Removed Values Added
First Time Zyxel uos
Zyxel usg Flex 700h
Zyxel usg Flex 200h
Zyxel usg Flex 500h
Zyxel usg Flex 200hp
Zyxel
Zyxel usg Flex 100h
References () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-insufficiently-protected-credentials-vulnerability-in-firewalls-10-22-2024 - () https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-insufficiently-protected-credentials-vulnerability-in-firewalls-10-22-2024 - Vendor Advisory
CWE CWE-522
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.8
CPE cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*

22 Oct 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 02:15

Updated : 2024-12-05 22:11


NVD link : CVE-2024-9677

Mitre link : CVE-2024-9677


JSON object : View

Products Affected

zyxel

  • usg_flex_500h
  • uos
  • usg_flex_200h
  • usg_flex_100h
  • usg_flex_200hp
  • usg_flex_700h
CWE

No CWE.