CVE-2024-20419 is a critical authentication bypass vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) that allows an unauthenticated, remote attacker to reset any user's password, including administrative accounts. This flaw, rated 10.0 CVSS, stems from improper password-change process implementation, enabling full system compromise via crafted HTTP requests. While not yet confirmed as actively exploited in the wild (KEV), public exploit code (Metasploit, Nuclei, ExploitDB) and significant community discussion (11 mentions) indicate a high likelihood of future exploitation. Media coverage further highlights the severity and potential for account takeover.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8-202112CPE matchmatch criteria | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.