Exploit released for Cisco SSM bug allowing admin password changes

Share:

Cisco warns that exploit code is now available for a maximum severity vulnerability that lets attackers change any user password on unpatched Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers.

As a Cisco Smart Licensing component, Cisco SSM On-Prem helps manage accounts and product licenses on an organization’s environment using a dedicated dashboard on the local network.

“The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory,” the company warned on Wednesday.

However, Cisco has yet to find evidence of attackers exploiting this security flaw (tracked as CVE-2024-20419) in the wild.

CVE-2024-20419 is caused by an unverified password change weakness in SSM On-Prem’s authentication system. This weakness lets unauthenticated attackers remotely change any user password (including those used for administrator accounts) without knowing the original credentials.

“This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco explained in July when it released security updates to address the flaw.

“A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.”

No workarounds are available for impacted systems, and all admins must upgrade to a fixed release to secure vulnerable SSM On-Prem servers.

Last month, Cisco also patched a critical vulnerability that allows attackers to add new users with root privileges and permanently crash Security Email Gateway (SEG) appliances using emails with malicious attachments and fixed an NX-OS zero-day (CVE-2024-20399) that had been exploited in the wild since April to install previously unknown malware as root on vulnerable MDS and Nexus switches.

Today, CISA warned admins to disable the legacy Cisco Smart Install feature after seeing it abused in recent attacks to steal sensitive data like system configuration files.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:42 am, Jun 22, 2025
weather icon 21°C
L: 19° | H: 23°
overcast clouds
Humidity: 70 %
Pressure: 1013 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 23°°C 0 mm 0% 16 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 82 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0.2 mm 20% 14 mph 84 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 29°°C 1 mm 100% 8 mph 86 % 1015 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 14 mph 88 % 1019 mb 0 mm/h
Today 4:00 am
weather icon
18° | 21°°C 0 mm 0% 10 mph 71 % 1013 mb 0 mm/h
Today 7:00 am
weather icon
17° | 20°°C 0 mm 0% 10 mph 70 % 1013 mb 0 mm/h
Today 10:00 am
weather icon
22° | 22°°C 0 mm 0% 12 mph 55 % 1014 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 15 mph 34 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 16 mph 46 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 14 mph 51 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 60 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 11 mph 73 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€88,619.94
-1.30%
Ethereum(ETH)
€1,963.25
-6.60%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.78
-3.77%
Solana(SOL)
€116.32
-4.20%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.133430
-5.73%
Shiba Inu(SHIB)
€0.000010
-5.31%
Pepe(PEPE)
€0.000008
-8.66%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top