CVE-2024-20419
published 2024-07-17CVE-2024-20419: A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change…
PriorityP196critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
80.64%
99.6th percentile
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_smart_software_manager_on-prem | — | — |
| cisco | smart | — | — |
| cisco | smart_software_manager_on-prem | < 8-202112 | 8-202112 |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for unauthenticated GET requests to /backend/settings/oauth_adfs as the initial token-harvesting step of the exploit. ↗
- →Monitor for the X-Xsrf-Token header being supplied in unauthenticated POST requests to the SSM On-Prem reset_password endpoints, indicating automated exploit tooling. ↗
- →Alert on JSON POST bodies containing both 'uid' and 'auth_token' fields to /backend/reset_password, which is the final password-change step of the exploit. ↗
- →A Metasploit auxiliary module exists for this vulnerability; detect exploitation attempts originating from Metasploit user-agent strings against SSM On-Prem HTTP endpoints. ↗
- →Public PoC exploit code is available; treat any SSM On-Prem version 8-202206 and earlier as actively exploitable and prioritize patching to 8-202212 or Release 9. ↗
- ·No workarounds exist for CVE-2024-20419; the only remediation is upgrading to a fixed release (8-202212 or Release 9). Detection/blocking rules alone are insufficient. ↗
- ·The vulnerability also affects installations earlier than Release 7.0, marketed as Cisco Smart Software Manager Satellite (SSM Satellite), not just SSM On-Prem. ↗
- ·The exploit requires no user interaction and no prior privileges, making it fully remotely exploitable with low attack complexity — CVSS score is 10.0. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Smart Software Manager On-Prem Password Change Vulnerability
vendor_cisco·2024-07-17·CVSS 10.0
CVE-2024-20419 [CRITICAL] CWE-620 Cisco Smart Software Manager On-Prem Password Change Vulnerability
Cisco Smart Software Manager On-Prem Password Change Vulnerability
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/sec
Cisco
Cisco Smart Software Manager On-Prem Password Change Vulnerability
vendor_cisco·CVSS 3.1
CVE-2024-20419 Cisco Smart Software Manager On-Prem Password Change Vulnerability
CVE-2024-20419: Cisco Smart Software Manager On-Prem Password Change Vulnerability
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-620, CWE-620
Bug IDs: CSCwk21399
GHSA
GHSA-5697-p67m-73p6: A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to
ghsa_unreviewed·2024-07-17
CVE-2024-20419 [CRITICAL] CWE-620 GHSA-5697-p67m-73p6: A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
VulnCheck
Cisco smart_software_manager_on-prem Unverified Password Change
vulncheck·2024·CVSS 10.0
CVE-2024-20419 [CRITICAL] Cisco smart_software_manager_on-prem Unverified Password Change
Cisco smart_software_manager_on-prem Unverified Password Change
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.
This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Affected: Cisco smart_software_manager_on-prem
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitati
Suricata
ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Successful Unauthenticated Password Reset (CVE-2024-20419)
suricata·2024-09-24·CVSS 10.0
CVE-2024-20419 [CRITICAL] ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Successful Unauthenticated Password Reset (CVE-2024-20419)
ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Successful Unauthenticated Password Reset (CVE-2024-20419)
Rule: alert http [$HTTP_SERVERS,$HOME_NET] any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Successful Unauthenticated Password Reset (CVE-2024-20419)"; flow:established,to_client; flowbits:isset,ET.CVE-2024-20419.request; http.stat_code; content:"200"; http.cookie; content:"XSRF|2d|TOKEN|3d|"; startswith; http.response_body; content:"|7b 22|uid|22 3a 22|"; startswith; content:"|22 2c 22|auth|5f|token|22 3a 22|"; fast_pattern; pcre:"/^(?:[a-z0-9]{64})\x22\x7d$/R"; reference:cve,2024-20419; reference:url,nvd.nist.gov/vuln/detail/CVE-2024-20419; reference:url,sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/
Suricata
ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Unauthenticated Password Change Attempt (CVE-2024-20419)
suricata·2024-09-24·CVSS 10.0
CVE-2024-20419 [CRITICAL] ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Unauthenticated Password Change Attempt (CVE-2024-20419)
ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Unauthenticated Password Change Attempt (CVE-2024-20419)
Rule: alert http $EXTERNAL_NET any -> [$HTTP_SERVERS,$HOME_NET] any (msg:"ET EXPLOIT Cisco Smart Software Manager On-Prem (SSM On-Prem) Unauthenticated Password Change Attempt (CVE-2024-20419)"; flow:established,to_server; flowbits:set,ET.CVE-2024-20419.request; urilen:37; http.method; content:"POST"; http.uri; content:"/backend/reset_password/generate_code"; fast_pattern; http.cookie; content:"XSRF|2d|TOKEN|3d|"; startswith; http.content_type; content:"application/json"; startswith; threshold: type limit, count 1, seconds 600, track by_src; reference:cve,2024-20419; reference:url,nvd.nist.gov/vuln/detail/CVE-2024-20419; reference:url,sec.cloudapps.cisco.com/security/cent
Exploit-DB
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
exploitdb·2025-04-10·CVSS 10.0
CVE-2024-20419 [CRITICAL] Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
---
# Exploit Title: Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
# Google Dork: N/A
# Date: 21/07/2024
# Exploit Author: Mohammed Adel
# Vendor Homepage: https://www.cisco.com
# Software Link:
https://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/smart-software-manager-satellite/datasheet-c78-734539.html
# Version: 8-202206 and earlier
# Tested on: Kali Linux
# CVE : CVE-2024-20419
# Security Advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy
# Technical Analysis: https://www.0xpolar.com/blog/CVE-2024-20419
import requests, sys
from urllib.parse import unquote
# Suppress SSL warnings
requests.packages.urllib3.disabl
Metasploit
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
metasploit·CVSS 10.0
CVE-2024-20419 [CRITICAL] Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
Cisco Smart Software Manager (SSM) On-Prem Account Takeover (CVE-2024-20419)
This module exploits an improper access control vulnerability in Cisco Smart Software Manager (SSM) On-Prem <= 8-202206. An unauthenticated remote attacker can change the password of any existing user, including administrative users.
Nuclei
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
nuclei·CVSS 10.0
CVE-2024-20419 [CRITICAL] Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process.
Template:
id: CVE-2024-20419
info:
name: Cisco SSM On-Prem <= 8-202206 - Password Reset Account Takeover
author: iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper
Bleepingcomputer
Cisco warns of backdoor admin account in Smart Licensing Utility
blogs_bleepingcomputer·2024-09-04·CVSS 9.8
CVE-2024-20439 [CRITICAL] Cisco warns of backdoor admin account in Smart Licensing Utility
## Cisco warns of backdoor admin account in Smart Licensing Utility
## Sergiu Gatlan
Cisco has removed a backdoor account in the Cisco Smart Licensing Utility (CSLU) that can be used to log into unpatched systems with administrative privileges.
CSLU is a Windows application that helps manage licenses and linked products on-premises without connecting them to Cisco's cloud-based Smart Software Manager solution.
The company says this critical vulnerability (CVE-2024-20439) allows unauthenticated attackers to log into unpatched systems remotely using an "undocumented static user credential for an administrative account."
"A successful exploit could allow the attacker to log in to the affected system with administrative privileges over the API of the Cisco Smart Licensing Utility applicat
Tenable
CVE-2024-20419: Cisco Smart Software Manager On-Prem Password Change Vulnerability
blogs_tenable·2024-08-09·CVSS 10.0
[CRITICAL] CVE-2024-20419: Cisco Smart Software Manager On-Prem Password Change Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Exploit released for Cisco SSM bug allowing admin password changes
blogs_bleepingcomputer·2024-08-08·CVSS 6.0
[MEDIUM] Exploit released for Cisco SSM bug allowing admin password changes
## Exploit released for Cisco SSM bug allowing admin password changes
## Sergiu Gatlan
Cisco warns that exploit code is now available for a maximum severity vulnerability that lets attackers change any user password on unpatched Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers.
As a Cisco Smart Licensing component, Cisco SSM On-Prem helps manage accounts and product licenses on an organization's environment using a dedicated dashboard on the local network.
"The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerability that is described in this advisory," the company warned on Wednesday.
However, Cisco has yet to find evidence of attackers exploiting this security flaw (tracked as CVE-2024-20419) in the wild.
CVE-2024-20419 is c
Checkpoint
22nd July – Threat Intelligence Report
blogs_checkpoint·2024-07-22
CVE-2024-27348 22nd July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 22nd July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 22nd July, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American Bassett Furniture Industries has been a victim of a ransomware attack that resulted in the encryption of data files and the shutdown of its manufacturing facilities. The attack has significantly disrupted the company’s operations, impacting its ability to fulfill orders despite keeping retail stores and its e-commerce
Bleepingcomputer
Cisco SSM On-Prem bug lets hackers change any user's password
blogs_bleepingcomputer·2024-07-17·CVSS 8.6
[HIGH] Cisco SSM On-Prem bug lets hackers change any user's password
## Cisco SSM On-Prem bug lets hackers change any user's password
## Sergiu Gatlan
Cisco has fixed a maximum severity vulnerability that allows attackers to change any user's password on vulnerable Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers, including administrators.
The flaw also impacts SSM On-Prem installations earlier than Release 7.0, known as Cisco Smart Software Manager Satellite (SSM Satellite).
As a Cisco Smart Licensing component, SSM On-Prem assists service providers and Cisco partners in managing customer accounts and product licenses.
Tracked as CVE-2024-20419, this critical security flaw is caused by an unverified password change weakness in SSM On-Prem's authentication system. Successful exploitation enables unauthenticated, remote attackers
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUyhttps://www.secpod.com/blog/critical-flaw-in-ciscos-secure-email-gateways-allows-attackers-to-control-the-device-completely/https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy
2024-07-17
Published
Exploited in the wild