CVE-2024-9677
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
22/10/2024
Last modified:
05/12/2024
Description
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:zyxel:uos:*:*:*:*:*:*:*:* | 1.30 (excluding) | |
| cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



