SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-20439

Cisco Smart Licensing Utility Static Credential Vulnerability

KEVCRITICAL 9.8EPSS 92.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 April 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
92.06% probability · 100th percentile
CISA KEV
Listed 31 March 2025 · due 21 April 2025
Weakness
CWE-912, CWE-798
Affected
cisco/smart license utility
Source
psirt@cisco.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw ; https://nvd.nist.gov/vuln/detail/CVE-2024-20439

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.