Cisco warns of backdoor admin account in Smart Licensing Utility
ID: 299673bf-0ce6-539c-a55b-ac0ff5aa90bf
STIX ID: report--299673bf-0ce6-539c-a55b-ac0ff5aa90bf
Feed Name: Bleeping Computer
Threat Score
Cisco patched two critical vulnerabilities in the Cisco Smart Licensing Utility: CVE-2024-20439, an undocumented static administrative credential that could allow unauthenticated remote administrative access, and CVE-2024-20440, an information-disclosure bug that can expose log files and API credentials; administrators are advised to migrate to fixed releases (2.3.0 is not vulnerable) and Cisco reports no evidence of exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
