ZeroHour
Security Affairspublished ()ingested @securityaffairs

Cisco Smart Licensing Utility flaws actively exploited in the wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-20439CVE-2024-20440CVE-2024-0305

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0305
A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic.

A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.

NVD description · AI analysis pending
7.567% PoC
  • ncast project ncast
CVE-2024-20439
Undocumented Static Admin Credential in Cisco Smart Licensing Utility

Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability.

Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes.

9.892% KEV
  • Cisco Smart Licensing Utility
moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate)
CVE-2024-20440
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

NVD description · AI analysis pending
7.552%
  • cisco smart license utility
Full article401 words · extracted from securityaffairs.com · click to collapse

Experts warn of the active exploitation of two recently patched security vulnerabilities affecting Cisco Smart Licensing Utility.

Cisco disclosed two vulnerabilities in its Smart Licensing Utility: CVE-2024-20439, a static credential backdoor, and CVE-2024-20440, an information disclosure flaw. Attackers can exploit the backdoor to access sensitive log files. While no active exploitation was initially observed, the publication of exploit details has led to recent attack activity.

“Multiple vulnerabilities in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running.” reads the advisory.

Below are the descriptions of the two vulnerabilities:

  • CVE-2024-20439 (CVSS score: 9.8) – The flaw is related to the presence of an undocumented static admin credential, allowing attackers to log in with administrative privileges via the Cisco Smart Licensing Utility API.
  • CVE-2024-20440 (CVSS score: 9.8) – The vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this issue by sending a specially crafted HTTP request to an affected device and obtain log files that contain sensitive data, including credentials that can be used to access the API.

The IT giant has already released software updates that address these flaws. There are no workarounds to address the two issues.

Researchers at SANS Internet Storm Center now warn that the two issues are actively exploited in attacks.

“These two vulnerabilities are somewhat connected. The first one is one of the many backdoors Cisco likes to equip its products with. A simple fixed password that can be used to obtain access. The second one is a log file that logs more than it should. Using the first vulnerability, an attacker may access the log file.” reads the advisory published by SANS. “A quick search didn’t show any active exploitation, but details, including the backdoor credentials, were published in a blog by Nicholas Starke shortly after Cisco released its advisory [2]. So it is no surprise that we are seeing some exploit activity”

SANS researchers warn that the group attempting to exploit the two vulnerabilities is also targeting configuration files and possibly CVE-2024-0305 (CVSS score: 5.3), likely exploiting a DVR vulnerability.

SANS’s advisory does not provide information about the identity or motivation of the attackers exploiting the two flaws.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cisco Smart Licensing Utility)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/175692/security/cisco-smart-licensing-utility-flaws-actively-exploited-in-the-wild.html