CVE-2024-20439
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 92.06%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-912
- Published
- 2024-09-04
- Last modified
- 2025-10-21
Affected products
- Cisco Cisco Smart License Utility
- Cisco Cisco Smart License Utility
- Cisco Cisco Smart License Utility
Weakness type
Related vulnerabilities
- CVE-2010-20103 — ProFTPD 1.3.3c Backdoor Command Execution
- CVE-2011-10018 — myBB 1.6.4 Backdoor Arbitrary Command Execution
- CVE-2025-34117 — Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
- CVE-2026-3587 — Hidden CLI Function Allows Root Access
- CVE-2024-39754 — A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte
- CVE-2024-45697 — D-Link WiFi router - Hidden Functionality
- CVE-2020-12504 — Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
- CVE-2022-3203 — ORing net IAP-420(+) Hidden Functionality