A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Aug 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-07-17T16:27:35.418Z
Updated: 2024-08-07T19:49:34.115Z
Reserved: 2023-11-08T15:08:07.664Z
Link: CVE-2024-20419
Vulnrichment
Updated: 2024-08-01T21:59:41.794Z
NVD
Status : Awaiting Analysis
Published: 2024-07-17T17:15:14.143
Modified: 2024-08-13T17:15:22.787
Link: CVE-2024-20419
Redhat
No data.