logo

Cisco's Smart Licensing Utility flaws suggest it's pretty dumb on security

ID: 63ca5a8b-93c4-51c7-a4a0-e50963589b43

STIX ID: report--63ca5a8b-93c4-51c7-a4a0-e50963589b43

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-09-05

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Cisco disclosed two critical vulnerabilities in its Smart Licensing Utility—CVE-2024-20439 permits an unauthenticated remote attacker to log in using a static administrative credential, and CVE-2024-20440 allows crafted HTTP requests to retrieve verbose debug logs containing sensitive data including credentials; both are rated CVSS 9.8, have no workaround, and fixed software updates are available, so affected users should patch immediately and ensure the service is not exposed unnecessarily.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.