logo

CISA Warns of Cisco Smart Licensing Utility Credential Vulnerability Exploited in Attacks

ID: 8bb102b2-d826-5259-817f-87f98b8bf91f

STIX ID: report--8bb102b2-d826-5259-817f-87f98b8bf91f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-04-01

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA added CVE-2024-20439—an undocumented static administrative credential in the Cisco Smart Licensing Utility—to its Known Exploited Vulnerabilities list after confirmation of active exploitation; the flaw (CVSS 9.8) allows unauthenticated remote administrative access and is often chained with CVE-2024-20440 to harvest sensitive data. Affected CSLU versions are 2.0.0–2.2.0 (2.3.0 is not vulnerable); CISA requires remediation for federal agencies and recommended mitigations include updating to 2.3.0, network segmentation, and monitoring for unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.