CVE-2024-20439
KEVmoderateUndocumented Static Admin Credential in Cisco Smart Licensing Utility
CISA: Cisco Smart Licensing Utility Static Credential Vulnerability
Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability.
What to do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes.
| Cisco Smart Licensing Utility | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
- Affected
- Cisco Smart Licensing Utility
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- smart license utility
- Weakness
- CWE-912, CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H