mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
21 lines
1.3 KiB
Markdown
21 lines
1.3 KiB
Markdown
### [CVE-2024-29976](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-29976)
|
||

|
||

|
||
C0%20&color=brighgreen)
|
||
C0%20&color=brighgreen)
|
||

|
||
|
||
### Description
|
||
|
||
** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED **The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
- https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
|
||
|
||
#### Github
|
||
- https://github.com/Pommaq/CVE-2024-29972-CVE-2024-29976-CVE-2024-29973-CVE-2024-29975-CVE-2024-29974-poc
|
||
- https://github.com/nomi-sec/PoC-in-GitHub
|
||
|