Cisco has disclosed a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem) that permits unauthenticated, remote attackers to change the passwords of any user, including administrative users. This flaw tracked as CVE-2024-20419, has been assigned the highest severity score of 10.
The vulnerability arises from improperly implementing the password-change process within the Cisco SSM On-Prem authentication system.
Attackers can exploit this flaw by sending specially crafted HTTP requests to an affected device. A successful exploit would allow attackers to gain access to the web UI or API with the privileges of the compromised user, potentially leading to unauthorized administrative control over the device.
Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files
The vulnerability impacts:
Cisco SSM Satellite has been renamed as Cisco Smart Software Manager. For releases earlier than Release 7.0, the product was called Cisco SSM Satellite. As of Release 7.0, it is known as Cisco SSM On-Prem.
Cisco has released software updates to address this vulnerability. The fixed releases are as follows:
Cisco SSM On-Prem Release | First Fixed Release |
---|---|
8-202206 and earlier | 8-202212 |
9 | Not vulnerable |
Customers are advised to upgrade to an appropriate fixed software release to secure their systems.
There are no workarounds available for this vulnerability. Cisco recommends that all administrators upgrade to the fixed software to mitigate the risk.
As of now, there have been no public announcements or evidence of malicious exploitation of this vulnerability. Cisco’s Product Security Incident Response Team (PSIRT) continues to monitor the situation.
Customers with service contracts should obtain security fixes through their usual update channels. Those without service contracts can contact the Cisco Technical Assistance Center (TAC) for assistance in obtaining the necessary updates.
How to Check Cisco Smart Software Manager On-Prem Version
172.16.0.1
, enter:texthttps://172.16.0.1:8443/admin
“Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!”- Free Demo
In the current software landscape, security breaches caused by untested or poorly tested code are…
Cybersecurity in mergers and acquisitions is crucial, as M&A activities represent key inflection points for…
In 2025, cybersecurity trends for CISOs will reflect a landscape that is more dynamic and…
Zero-trust architecture has become essential for securing operations in today’s hyper-connected world, where corporate network…
The Chrome team has officially promoted Chrome 136 to the stable channel for Windows, Mac,…
By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…