Executive brief
Cisco Smart Software Manager On-Prem is a tool used by organizations to manage software licenses locally without needing a direct connection to Cisco's cloud. A security flaw in its web interface could allow a standard user to steal the login credentials of other active administrators. If exploited, this would allow a low-level user to gain full administrative control over the licensing system, potentially disrupting operations or altering license configurations.
Technical details
A privilege escalation vulnerability exists in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) due to the improper transmission of sensitive user information (CWE-201). An authenticated, remote attacker with 'System User' privileges can exploit this by sending a crafted message to the host and intercepting session credentials contained in subsequent status messages. This vulnerability specifically affects users currently logged in via the web interface; SSH sessions are not impacted. Successful exploitation allows an attacker to elevate their privileges from a low-level user to an administrator. Cisco has released fixed software in version 9-202601.
Affected products
- Cisco Smart Software Manager On-Prem (SSM On-Prem) 9-202510 and earlier
Timeline
- 2026-04-01: advisory: Initial public release of Cisco advisory cisco-sa-cssm-priv-esc-xRAnOuO8
- 2026-04-01: patched: Fixed in release 9-202601