Threat Advisory

Cisco Smart Licensing Utility Vulnerabilities Require Immediate Attention

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Cisco has identified critical vulnerabilities in the Cisco Smart Licensing Utility (CSLU) under CVE-2024-20439 and CVE-2024-20440, allowing unauthorized access and information disclosure on unpatched systems. CVE-2024-20439 permits unauthenticated attackers to log in remotely with administrative privileges using undocumented static credentials, while CVE-2024-20440 enables attackers to exploit crafted HTTP requests to access sensitive log files containing API credentials and other data. This exposure emphasizes the urgency for users to migrate to fixed releases, particularly as CVE-2024-20440 can lead to significant data breaches if left unaddressed. Cisco's Product Security Incident Response Team (PSIRT) has not observed public exploitation of these vulnerabilities, but the potential impact is severe, underscoring the need for immediate action by affected organizations to mitigate risks​[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A Cisco has identified critical vulnerabilities in the Cisco Smart Licensing Utility (CSLU) under CVE-2024-20439 and CVE-2024-20440, allowing unauthorized access and information disclosure on unpatched systems. CVE-2024-20439 permits unauthenticated attackers to log in remotely with administrative privileges using undocumented static credentials, while CVE-2024-20440 enables attackers to exploit crafted HTTP requests to access sensitive log files containing API credentials and other data. This exposure emphasizes the urgency for users to migrate to fixed releases, particularly as CVE-2024-20440 can lead to significant data breaches if left unaddressed. Cisco's Product Security Incident Response Team (PSIRT) has not observed public exploitation of these vulnerabilities, but the potential impact is severe, underscoring the need for immediate action by affected organizations to mitigate risks​[emaillocker id="1283"]

 

  • CVE-2024-20440: Unauthenticated threat actors can exploit this vulnerability to access sensitive log files by sending specially crafted HTTP requests, potentially exposing API credentials and other confidential information.

 

Organizations using Cisco Smart Licensing Utility must prioritize security updates to protect against these critical vulnerabilities, as the risks of exploitation remain high if adequate measures are not implemented.

RECOMMENDATION:

We strongly recommend you update Cisco products as given below:

  • Cisco's Smart Licensing Utility update to version 2.3.0.
  • Cisco Adaptive Security Appliance (ASA) software update to version 9.22(1.1).
  • Cisco Firepower Threat Defense (FTD) software update to version 7.6.0.

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/cisco-warns-of-backdoor-admin-account-in-smart-licensing-utility/

[/emaillocker]
crossmenu