Junglewise Threat Intelligence

CVE-2024-20439: Cisco Smart Licensing Utility Static Credential Vulnerability

CVE-2024-20439 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-03-31

Vendors: Cisco.

Executive brief

Cisco Smart Licensing Utility (CSLU) contains an undocumented static administrative credential. An unauthenticated remote attacker can exploit this by using the hardcoded credentials to log in to the system, gaining full administrative rights over the application API.

Affected products

  • Cisco Smart Licensing Utility (CSLU) 2.0.0 up to (excluding) 2.3.0

Timeline

  • 2024-09-04: disclosed: Initial NVD publication and Cisco advisory release
  • 2025-03-31: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-03-31: exploited: Confirmed as exploited in the wild per CISA KEV entry