Executive brief
A vulnerability in Cisco Smart Software Manager On-Prem could allow an unauthenticated attacker to take full control of the system. By sending a malicious request to an exposed internal service, an attacker can execute commands with the highest level of administrative privileges. This could lead to a complete compromise of the management platform, unauthorized access to licensing data, and disruption of service operations.
Technical details
The vulnerability (CWE-668) exists due to the unintentional exposure of an internal service API in Cisco Smart Software Manager On-Prem. An unauthenticated, remote attacker can exploit this by sending crafted requests directly to the API of the exposed service. Successful exploitation grants the attacker arbitrary command execution on the underlying Linux operating system with root privileges. Cisco has released software updates to address this issue, and there are no known workarounds. The fix is included in release 9-202601.
Affected products
- Cisco Smart Software Manager On-Prem (SSM On-Prem) 9-202502 to 9-202510
Timeline
- 2026-04-01: disclosed
- 2026-04-01: advisory
- 2026-04-01: patched