PT-2024-5066 · Cisco · Cisco Smart Software Manager On-Prem

Mohammed Adel

·

Published

2024-07-17

·

Updated

2026-03-13

·

CVE-2024-20419

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Cisco Smart Software Manager On-Prem versions 8-202206 and earlier
Description: A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Recommendations: For Cisco Smart Software Manager On-Prem versions 8-202206 and earlier, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the affected device to minimize the risk of exploitation. Avoid using the vulnerable authentication system until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05593
CVE-2024-20419

Affected Products

Cisco Smart Software Manager On-Prem