PT-2024-5915 · Cisco · Cisco Smart Licensing Utility

Eric Vance

·

Published

2024-09-04

·

Updated

2026-05-03

·

CVE-2024-20439

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Smart Licensing Utility (affected versions not specified)
Description An issue in the Cisco Smart Licensing Utility (CSLU) allows an unauthenticated, remote attacker to log into an affected system. This is caused by an undocumented static user credential for an administrative account. A successful exploit enables the attacker to gain administrative rights over the CSLU application API. The software is an electron application built on a REST API written in golang.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Hidden Functionality

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-06720
BDU:2024-06721
CVE-2024-20439

Affected Products

Cisco Smart Licensing Utility