U.S. CISA adds Cisco Smart Licensing Utility flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-0305 | A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872. NVD description · AI analysis pending | 7.5 | 67% | PoC |
| — | |
| CVE-2024-20439 | Undocumented Static Admin Credential in Cisco Smart Licensing Utility Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability. Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes. | 9.8 | 92% | KEV |
| moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate) | |
| CVE-2024-20440 | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API. NVD description · AI analysis pending | 7.5 | 52% |
| — |
Full article498 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Smart Licensing Utility flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Smart Licensing Utility vulnerability, tracked as CVE-2024-20439, to its Known Exploited Vulnerabilities (KEV) catalog.
Last week, Cisco disclosed two vulnerabilities in its Smart Licensing Utility: CVE-2024-20439, a static credential backdoor, and CVE-2024-20440, an information disclosure flaw. Attackers can exploit the backdoor to access sensitive log files. While no active exploitation was initially observed, the publication of exploit details has led to recent attack activity.
“Multiple vulnerabilities in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running.” reads the advisory.
Below are the descriptions of the two vulnerabilities:
- CVE-2024-20439 (CVSS score: 9.8) – The flaw is related to the presence of an undocumented static admin credential, allowing attackers to log in with administrative privileges via the Cisco Smart Licensing Utility API.
- CVE-2024-20440 (CVSS score: 9.8) – The vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this issue by sending a specially crafted HTTP request to an affected device and obtain log files that contain sensitive data, including credentials that can be used to access the API.
The IT giant also released software updates that address these flaws. There are no workarounds to address the two issues.
Researchers at SANS Internet Storm Center warned that the two issues are actively exploited in attacks.
“These two vulnerabilities are somewhat connected. The first one is one of the many backdoors Cisco likes to equip its products with. A simple fixed password that can be used to obtain access. The second one is a log file that logs more than it should. Using the first vulnerability, an attacker may access the log file.” reads the advisory published by SANS. “A quick search didn’t show any active exploitation, but details, including the backdoor credentials, were published in a blog by Nicholas Starke shortly after Cisco released its advisory [2]. So it is no surprise that we are seeing some exploit activity”
SANS researchers warned that the group attempting to exploit the two vulnerabilities is also targeting configuration files and possibly CVE-2024-0305 (CVSS score: 5.3), likely exploiting a DVR vulnerability.
SANS’s advisory does not provide information about the identity or motivation of the attackers exploiting the two flaws.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by April 21, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Cisco Smart Licensing Utility vulnerability)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/176073/hacking/u-s-cisa-adds-cisco-smart-licensing-utility-flaw-known-exploited-vulnerabilities-catalog.html