Vulnerability Description
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Uos | < 1.30 |
| Zyxel | Usg Flex 100H | - |
| Zyxel | Usg Flex 200H | - |
| Zyxel | Usg Flex 200Hp | - |
| Zyxel | Usg Flex 500H | - |
| Zyxel | Usg Flex 700H | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-9677?
CVE-2024-9677 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain p...
How severe is CVE-2024-9677?
CVE-2024-9677 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9677?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Uos, Zyxel Usg Flex 100H, Zyxel Usg Flex 200H, Zyxel Usg Flex 200Hp, Zyxel Usg Flex 500H.