The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
References
Configurations
No configuration.
History
23 Oct 2024, 15:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Oct 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-22 02:15
Updated : 2024-10-23 15:12
NVD link : CVE-2024-9677
Mitre link : CVE-2024-9677
CVE.ORG link : CVE-2024-9677
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials