logo

Maximum-severity Cisco vulnerability allows attackers to change admin passwords

ID: 97b2290d-2d23-5f49-a956-c8face550ea8

STIX ID: report--97b2290d-2d23-5f49-a956-c8face550ea8

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-07-18

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Cisco published patches for CVE-2024-20419, a maximum-severity (CVSS 3.1 10.0) authentication vulnerability in Cisco Smart Software Manager On‑Prem and SSM Satellite that allows an unauthenticated remote attacker to change any user's password, including administrators. The flaw is low complexity, affects confidentiality, integrity, and availability, has no workarounds, and Cisco recommends upgrading affected versions (upgrade to 8-202212 or preferably version 9); no in-the-wild exploitation has been reported yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.