Exploit released for Cisco SSM bug allowing admin password changes

Share:

Cisco warns that exploit code is now available for a maximum severity vulnerability that lets attackers change any user password on unpatched Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers.

As a Cisco Smart Licensing component, Cisco SSM On-Prem helps manage accounts and product licenses on an organization’s environment using a dedicated dashboard on the local network.

“The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory,” the company warned on Wednesday.

However, Cisco has yet to find evidence of attackers exploiting this security flaw (tracked as CVE-2024-20419) in the wild.

CVE-2024-20419 is caused by an unverified password change weakness in SSM On-Prem’s authentication system. This weakness lets unauthenticated attackers remotely change any user password (including those used for administrator accounts) without knowing the original credentials.

“This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco explained in July when it released security updates to address the flaw.

“A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.”

No workarounds are available for impacted systems, and all admins must upgrade to a fixed release to secure vulnerable SSM On-Prem servers.

Last month, Cisco also patched a critical vulnerability that allows attackers to add new users with root privileges and permanently crash Security Email Gateway (SEG) appliances using emails with malicious attachments and fixed an NX-OS zero-day (CVE-2024-20399) that had been exploited in the wild since April to install previously unknown malware as root on vulnerable MDS and Nexus switches.

Today, CISA warned admins to disable the legacy Cisco Smart Install feature after seeing it abused in recent attacks to steal sensitive data like system configuration files.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:18 pm, Jun 21, 2025
weather icon 30°C
L: 29° | H: 32°
overcast clouds
Humidity: 39 %
Pressure: 1015 mb
Wind: 10 mph SE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 99%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
29° | 32°°C 0.73 mm 73% 10 mph 45 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 1 mm 100% 15 mph 78 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 23°°C 0 mm 0% 13 mph 78 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
18° | 27°°C 0.38 mm 38% 11 mph 82 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 30°°C 0 mm 0% 10 mph 39 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 28°°C 0.73 mm 73% 7 mph 45 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 23°°C 1 mm 100% 7 mph 65 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 10 mph 78 % 1013 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 67 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 12 mph 48 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 15 mph 48 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,843.42
0.00%
Ethereum(ETH)
€2,099.35
-2.46%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.83
-0.30%
Solana(SOL)
€122.01
-0.83%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.139270
-1.05%
Shiba Inu(SHIB)
€0.000010
-2.12%
Pepe(PEPE)
€0.000009
-1.19%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top