Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20439 | Undocumented Static Admin Credential in Cisco Smart Licensing Utility Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability. Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes. | 9.8 | 92% | KEV |
| moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate) | |
| CVE-2024-20440 | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API. NVD description · AI analysis pending | 7.5 | 52% |
| — |
Full article412 words · extracted from helpnetsecurity.com · click to collapse
CVE-2024-20439, a static credential vulnerability in the Cisco Smart Licensing Utility, is being exploited by attackers in the wild, CISA has confirmed on Monday by adding the flaw to its Known Exploited Vulnerabilities catalog.
Cisco has followed up with a confirmation by updating the security advisory covering CVE-2024-20439 and CVE-2024-20440, an information disclosure flaw in the same software.
“In March 2025, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of this vulnerability in the wild,” the company said.
All this came two weeks after Johannes Ullrich, Dean of Research at the SANS Technology Institute, flagged exploit attempts of CVE-2024-20439 (and possibly CVE-2024-20440).
About CVE-2024-20439 and CVE-2024-20440
Cisco Smart License Utility Manager (CSLU) is a Windows and Linux application that’s used by Cisco customers to administer licenses and associated Product Instances from their premises.
CVE-2024-20439 and CVE-2024-20440 have been publicly disclosed by Cisco in early September 2024, when they released version 2.3.0 of the software that included fixes for both. The company urged customers to upgrade to it as a workaround wasn’t available.
CVE-2024-20439 allows unauthenticated, remote attackers to log in to an affected system by using a static administrative credential. “A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application,” the company explained.
CVE-2024-20440 allows unauthenticated, remote attackers to obtain log files (and sensitive data in them, e.g. API credentials) by sending a crafted HTTP request to an affected device.
The good news is that the flaws could only be exploited if the utility was actively running. The bad news is that the vulnerabilities could be exploited independently from one another.
But while security researcher Nicholas Starke released a write-up on CVE-2024-20439 and the static admin credential in question in late September 2024, it took until March 2025 for security researchers to spot exploitation attempts.
What to do?
Whether these attemps have been successful is unknown, though CVE-2024-20439’s inclusion in CISA’s KEV catalog would suggest at least some have.
CISA has given US federal agencies until April 21 to “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”
Other Cisco customers that use the utility are advised to upgrade it to the fixed version.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/03/attackers-are-leveraging-cisco-smart-licensing-utility-static-admin-credentials-cve-2024-20439/