PT-2024-5288 · Zyxel · Zyxel Wbe660S
Alessandro Sgreccia
·
Published
2024-02-16
·
Updated
2025-01-22
·
CVE-2024-1575
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zyxel WBE660S versions 6.70(ACGG.3) and earlier
Description
The issue is related to improper privilege management, which could allow an authenticated user to escalate privileges and download configuration files on a vulnerable device. This is due to deficiencies in access control.
Recommendations
For versions 6.70(ACGG.3) and earlier, update to a version that addresses the improper privilege management issue to prevent privilege escalation and unauthorized configuration file downloads.
As a temporary workaround, consider restricting access to configuration files and limiting user privileges until a patch is available.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Wbe660S