ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Cisco Warns of Critical Vulnerabilities in Smart Licensing Utility

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20439
Undocumented Static Admin Credential in Cisco Smart Licensing Utility

Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability.

Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes.

9.892% KEV
  • Cisco Smart Licensing Utility
moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate)
CVE-2024-20440
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

NVD description · AI analysis pending
7.552%
  • cisco smart license utility
Full article380 words · extracted from infosecurity-magazine.com · click to collapse

Cisco has warned customers of critical vulnerabilities in its Smart Licensing Utility product, urging them to apply software updates to protect against attacks.

The two vulnerabilities, which are not dependent on one another, could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running. They each have a CVSS score of 9.8, giving them a critical rating.

There are no workarounds that address these vulnerabilities, meaning customers must apply new software updates provided by Cisco to prevent exploitation.

The vulnerabilities affect versions 2.0.0, 2.1.0 and 2.2.0 of the Cisco Smart Licensing Utility.

Cisco said it is not aware of any malicious exploitation of these vulnerabilities as of September 4, 2024.

The Cisco Smart License Utility Manager is a Windows-based application that enables customers to administer licenses and their associated Product Instances from their premises.

How the Vulnerabilities Can be Exploited

The first vulnerability highlighted, CVE-2024-20439, can allow a remote attacker to use a static administrative credential to log in to an affected system.

This flaw is due to an undocumented static user credential for an administrative account. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the application programming interface (API) of the Cisco Smart Licensing Utility application.

The second listed vulnerability, CVE-2024-20440, may enable an unauthenticated attacker to access sensitive information by sending a crafted HTTP request to an affected device.

This is due to excessive verbosity in a debug log file. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

Cisco noted that these vulnerabilities are not exploitable unless Cisco Smart Licensing Utility was started by a user and is actively running.

Cisco Products Targeted by Nation States

Cisco has highlighted several campaigns by nation-state threat actors that have targeted vulnerabilities in its products so far in 2024.

In April, the firm highlighted a sophisticated cyber espionage campaign dubbed ArcaneDoor by a state-sponsored actor, which exploited two vulnerabilities in Cisco firewall platforms.

Cisco also revealed in July that it had patched a zero-day vulnerability exploited by Chinese state-backed actors to compromise Cisco Nexus switches. 

Image credit: CryptoFx / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisco-critical-vulnerabilities/