CVE-2024-9677

The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versionsĀ could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login administrator. Note that this attack could be successful only if the administrator has not logged out.
Configurations

No configuration.

History

22 Oct 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-22 02:15

Updated : 2024-10-22 02:15


NVD link : CVE-2024-9677

Mitre link : CVE-2024-9677

CVE.ORG link : CVE-2024-9677


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials