CVE-2024-20440 is a high-severity information disclosure vulnerability in Cisco Smart Licensing Utility (CSLU) caused by excessive verbosity in a debug log file. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to obtain sensitive data, including API credentials. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this flaw allows for full confidentiality compromise. While not yet in the KEV catalog, Nuclei templates exist for exploitation, and it has garnered significant community discussion and media coverage, including reports of active exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:smart_license_utility:2.0.0:*:*:*:*:*:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:smart_license_utility:2.1.0:*:*:*:*:*:*:* | ||
2.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:smart_license_utility:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.