A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential.
This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to log in to the affected system. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco smart License Utility
|
|
Weaknesses | CWE-798 | |
CPEs | cpe:2.3:a:cisco:smart_license_utility:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cisco smart License Utility
|
Wed, 04 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco cisco Smart License Utility |
|
CPEs | cpe:2.3:a:cisco:cisco_smart_license_utility:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cisco
Cisco cisco Smart License Utility |
|
Metrics |
ssvc
|
Wed, 04 Sep 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to log in to the affected system. A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility application. | |
Title | Cisco Smart Licensing Utility Static Credential Vulnerability | |
Weaknesses | CWE-912 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-09-04T16:28:39.669Z
Updated: 2024-09-06T03:55:16.157Z
Reserved: 2023-11-08T15:08:07.670Z
Link: CVE-2024-20439
Vulnrichment
Updated: 2024-09-04T17:45:35.659Z
NVD
Status : Analyzed
Published: 2024-09-04T17:15:13.210
Modified: 2024-09-13T19:35:32.477
Link: CVE-2024-20439
Redhat
No data.