Unauthenticated Password Change Vulnerability in Cisco SSM On-Prem

CVE-2024-20419
10CRITICAL

Key Information

Vendor
Cisco
Status
Cisco Smart Software Manager On-prem
Vendor
CVE Published:
17 July 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability with the identifier CVE-2024-20419 is a severe one in Cisco's Smart Software Manager On-Prem software. It enables an unauthenticated attacker to change the password of any user, including administrative users, by sending specially crafted HTTP requests to the affected system. Due to the high severity and ease of exploitation, it is crucial for organizations to apply the available patches promptly. While there are no known instances of exploitation in the wild yet, the potential impact of this vulnerability, especially in industries such as finance, utilities, and government, is significant. It is part of a set of issues addressed by Cisco, with another critical flaw also being patched.

Affected Version(s)

Cisco Smart Software Manager On-Prem = 8-202206

News Articles

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • First article discovered by Help Net Security

  • Vulnerability published.

  • Vulnerability Reserved.

  • 👾

    Exploit exists.

Collectors

NVD DatabaseMitre Database5 News Article(s)
.