CVE-2024-9677

CVSS V2 None CVSS V3 None
Description
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Overview
  • CVE ID
  • CVE-2024-9677
  • Assigner
  • Zyxel
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-22T01:19:53.188Z
  • Last Modified Date
  • 2024-10-22T01:19:53.188Z
History
Created Old Value New Value Data Type Notes
2024-10-22 13:55:36 Added to TrackCVE