nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29976 CVE-2024-29976
MEDIUM
Record summary
CVE-2024-29976 has a selected CVSS score of 6.5 (medium); EIP currently links 1 repository PoC.
Description
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 6, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
NAS326 firmwareBrowse Zyxel / NAS326 firmwareDefault status: unaffected | CVE List | < V5.21(AAZF.17)C0 | affected |
| Through 5.21(aazf.16)c0 | affected | ||
NAS542 firmwareBrowse Zyxel / NAS542 firmwareDefault status: unaffected | CVE List | < V5.21(ABAG.14)C0 | affected |
| Through 5.21(abag.13)c0 | affected |
Proofs of concept
1Repository PoCs
GitHubPommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-pocRepository PoCby PommaqStars: 4Not analyzed5 files
References
3outpost24.com
https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities zyxel.comVendor advisory
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-nas-products-06-04-2024