CVE-2024-20439 is a critical vulnerability in Cisco Smart Licensing Utility (CSLU) that allows an unauthenticated, remote attacker to log in using a static, undocumented administrative credential. This flaw affects all versions of Cisco Smart Licensing Utility. With a CVSS score of 9.8 (Critical), exploitation is straightforward, requiring no user interaction, and grants administrative control over the CSLU application API, leading to full compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage, with public exploit templates available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:smart_license_utility:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.