logo

High-Severity Cisco Bug Grants Attackers Password Access

ID: 83b36234-d7c7-592a-8217-fea4a87f4a52

STIX ID: report--83b36234-d7c7-592a-8217-fea4a87f4a52

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-07-18

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Cisco published a patch for CVE-2024-20419, a maximum-severity (CVSS 10) unauthenticated vulnerability affecting SSM On‑Prem and SSM Satellite that can allow attackers to change any user or admin password by sending crafted HTTP requests. The flaw has low attack complexity, high impact to confidentiality, integrity, and availability, no workarounds, and affects systems commonly used by financial institutions, utilities, service providers, and government organizations; users are advised to apply the patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.