CVE-2024-20401 and CVE-2024-20419
ID: 836e09d7-320a-56e6-abaf-fa763f15a664
STIX ID: report--836e09d7-320a-56e6-abaf-fa763f15a664
Feed Name: Arctic Wolf Blog
**Executive Summary:** On July 17, 2024, Cisco disclosed two critical vulnerabilities—CVE-2024-20401 (arbitrary file write in Cisco Secure Email Gateway, CVSS 9.8) and CVE-2024-20419 (unauthenticated password change in Cisco Smart Software Manager On-Prem, CVSS 10.0)—that could allow attackers to gain administrative or root access and perform configuration changes or code execution; there are no confirmed in-the-wild exploit reports and Cisco recommends applying provided patches and upgrading affected software to fixed versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
