6.7
CVE-2024-29975
- EPSS 0.24%
- Published 04.06.2024 02:15:48
- Last modified 22.01.2025 22:48:49
- Source security@zyxel.com.tw
- Teams watchlist Login
- Open Login
** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.
Data is provided by the National Vulnerability Database (NVD)
Zyxel ≫ Nas326 Firmware Version < 5.21\(aazf.17\)c0
Zyxel ≫ Nas542 Firmware Version < 5.21\(abag.14\)c0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.469 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
security@zyxel.com.tw | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.