CVE-2024-9677

Insufficiently Protected Credentials (CWE-522)

Published: Oct 22, 2024 / Updated: 29d ago

010
CVSS 5.5EPSS 0.04%Medium
CVE info copied to clipboard

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Timeline

CVE Assignment

NVD published the first details for CVE-2024-9677

Oct 22, 2024 at 2:15 AM
CVSS

A CVSS base score of 5.5 has been assigned.

Oct 22, 2024 at 2:15 AM / nvd
First Article

Feedly found the first article mentioning CVE-2024-9677. See article

Oct 22, 2024 at 2:21 AM / National Vulnerability Database
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Oct 22, 2024 at 2:21 AM
EPSS

EPSS Score was set to: 0.04% (Percentile: 9.7%)

Oct 22, 2024 at 10:47 AM
Static CVE Timeline Graph

Affected Systems

Zyxel/usg_flex_firmware
+null more

Links to Mitre Att&cks

T1558.003: Kerberoasting
+null more

Attack Patterns

CAPEC-102: Session Sidejacking
+null more

News

Security Update for Zyxel
Development Last Updated: 10/23/2024 CVEs: CVE-2024-9677
Medium - CVE-2024-9677 - The insufficiently protected credentials...
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to...
Insufficiently Protected Credentials Vulnerability in USG FLEX H Series uOS
USG - MEDIUM - CVE-2024-9677 The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
CVE-2024-9677 | Zyxel USG FLEX H uOS up to 1.21 CLI insufficiently protected credentials
A vulnerability was found in Zyxel USG FLEX H uOS up to 1.21 . It has been rated as problematic . This issue affects some unknown processing of the component CLI . The manipulation leads to insufficiently protected credentials. The identification of this vulnerability is CVE-2024-9677 . The attack needs to be approached locally. There is no exploit available.
CVE-2024-9677
Gravedad 3.1 (CVSS 3.1 Base Score) Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
See 3 more articles and social media posts

CVSS V3.1

Attack Vector:Local
Attack Complexity:Low
Privileges Required:Low
User Interaction:None
Scope:Unchanged
Confidentiality:High
Integrity:None
Availability Impact:None

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI