AI analysis
Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has a critical flaw in the Cisco Smart Licensing Utility management API caused by missing authentication and improper input validation (CWE-23, path traversal). An unauthenticated remote attacker can trigger it by sending a crafted request to the affected API, with no user interaction required. A successful attack can write or modify arbitrary system files or cause a denial-of-service condition; the CVSS 3.1 score is 9.1 with no confidentiality impact (C:N/I:H/A:H). Organizations that run this on-premises Cisco licensing application are affected, but specific version ranges were not included in the provided data. There is no known public proof of concept and the issue is not listed in CISA KEV.
What to do: Keep Cisco License On-Prem (SSM On-Prem) off the public internet and restrict the Smart Licensing Utility management API to trusted management networks until Cisco publishes a fix. Apply the vendor patch as soon as a fixed release is available, and review the host for unexpected file changes or service outages. Affected and fixed version numbers were not in the source data, so do not assume a particular build is safe.
Affected
| Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem / SSM On-Prem), Cisco Smart Licensing Utility API | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition.