ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20439
Undocumented Static Admin Credential in Cisco Smart Licensing Utility

Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability.

Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes.

9.892% KEV
  • Cisco Smart Licensing Utility
moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate)
CVE-2024-20440
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

NVD description · AI analysis pending
7.552%
  • cisco smart license utility
CVE-2024-20469
A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attac

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

NVD description · AI analysis pending
6.7<1%
  • cisco identity services engine
Full article369 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 05, 2024

Cisco has released security updates for two critical security flaws impacting its Smart Licensing Utility that could allow unauthenticated, remote attackers to elevate their privileges or access sensitive information.

A brief description of the two vulnerabilities is below -

  • CVE-2024-20439 (CVSS score: 9.8) - The presence of an undocumented static user credential for an administrative account that an attacker could exploit to log in to an affected system
  • CVE-2024-20440 (CVSS score: 9.8) - A vulnerability arising due to an excessively verbose debug log file that an attacker could exploit to access such files by means of a crafted HTTP request and obtain credentials that can be used to access the API

While these shortcomings are not dependent on each other for them to be successful, Cisco notes in its advisory that they "are not exploitable unless Cisco Smart Licensing Utility was started by a user and is actively running."

The flaws, which were discovered during internal security testing, also do not affect Smart Software Manager On-Prem and Smart Software Manager Satellite products.

Users of Cisco Smart License Utility versions 2.0.0, 2.1.0, and 2.2.0 are advised to update to a fixed release. Version 2.3.0 of the software is not susceptible to the bug.

Cisco has also released updates to resolve a command injection vulnerability in its Identity Services Engine (ISE) that could permit an authenticated, local attacker to run arbitrary commands on an underlying operating system and elevate privileges to root.

The flaw, tracked as CVE-2024-20469 (CVSS score: 6.0), requires an attacker to have valid administrator privileges on an affected device.

"This vulnerability is due to insufficient validation of user-supplied input," the company said. "An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root."

It impacts the following versions -

  • Cisco ISE 3.2 (3.2P7 - Sep 2024)
  • Cisco ISE 3.3 (3.3P4 - Oct 2024)

The company has also warned that a proof-of-concept (PoC) exploit code is available, although it's not aware of any malicious exploitation of the bug.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/09/cisco-fixes-two-critical-flaws-in-smart.html