CVE-2024-20439
Cisco Smart Licensing Utility Static Credential Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 April 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 92.06% probability · 100th percentile
- CISA KEV
- Listed 31 March 2025 · due 21 April 2025
- Weakness
- CWE-912, CWE-798
- Affected
- cisco/smart license utility
- Source
- psirt@cisco.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw ; https://nvd.nist.gov/vuln/detail/CVE-2024-20439
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.