CVE-2024-29976: Medium severity zyxel nas326 vulnerability
UNSUPPORTED WHEN ASSIGNED The improper privilege management vulnerability in the command “showallsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29976?
The severity of CVE-2024-29976 is considered critical due to improper privilege management that can be exploited by authenticated attackers.
How do I fix CVE-2024-29976?
To fix CVE-2024-29976, update Zyxel NAS326 firmware to version V5.21(AAZF.17)C0 or NAS542 firmware to version V5.21(ABAG.14)C0.
What products are affected by CVE-2024-29976?
CVE-2024-29976 affects Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and Zyxel NAS542 firmware versions before V5.21(ABAG.14)C0.
Can CVE-2024-29976 be exploited remotely?
CVE-2024-29976 cannot be exploited remotely as it requires authenticated access to the affected devices.
What should I do if I can't update my Zyxel NAS devices for CVE-2024-29976?
If you cannot update your Zyxel NAS devices for CVE-2024-29976, consider disabling remote management features and limiting access to trusted users only.