PT-2024-5914 · Cisco · Cisco Smart License Utility

Eric Vance

·

Published

2024-09-04

·

Updated

2025-06-03

·

CVE-2024-20440

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Smart License Utility (affected versions not specified)
Description The issue is related to the disclosure of information through registration files. It is due to excessive verbosity in a debug log file, which could allow an unauthenticated, remote attacker to access sensitive information by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-06720
CVE-2024-20440

Affected Products

Cisco Smart License Utility