A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 31 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco smart Software Manager On-prem |
|
| CPEs | cpe:2.3:a:cisco:smart_software_manager_on-prem:8-202206:*:*:*:*:*:*:* | |
| Vendors & Products |
Cisco
Cisco smart Software Manager On-prem |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2025-02-13T17:32:31.164Z
Reserved: 2023-11-08T15:08:07.664Z
Link: CVE-2024-20419
Updated: 2024-08-01T21:59:41.794Z
Status : Analyzed
Published: 2024-07-17T17:15:14.143
Modified: 2025-07-31T15:19:25.703
Link: CVE-2024-20419
No data.
OpenCVE Enrichment
No data.
Weaknesses