Maximum-severity Cisco vulnerability allows attackers to change admin passwords
ID: 97b2290d-2d23-5f49-a956-c8face550ea8
STIX ID: report--97b2290d-2d23-5f49-a956-c8face550ea8
Feed Name: The Register (Security)
Cisco published patches for CVE-2024-20419, a maximum-severity (CVSS 3.1 10.0) authentication vulnerability in Cisco Smart Software Manager On‑Prem and SSM Satellite that allows an unauthenticated remote attacker to change any user's password, including administrators. The flaw is low complexity, affects confidentiality, integrity, and availability, has no workarounds, and Cisco recommends upgrading affected versions (upgrade to 8-202212 or preferably version 9); no in-the-wild exploitation has been reported yet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
