Cisco has addressed a critical vulnerability, tracked as CVE-2024-20419 (CVSS score of 10.0), in Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers that allows attackers to change any user’s password.<\/p>\n\n\n\n
The issue is due to an improper implementation in the password-change process. Threat actors can trigger the vulnerability by sending specially crafted HTTP requests to vulnerable devices. <\/p>\n\n\n\n
“A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users.” reads the advisory<\/strong><\/a> published by the IT giant. “This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.”<\/em><\/p>\n\n\n\n
The security researcher Mohammed Adel discovered this vulnerability. <\/p>\n\n\n\n
The advisory states that there is no workaround for this flaw.<\/p>\n\n\n\n
Pierluigi\u00a0Paganini<\/strong><\/a><\/p>\n\n\n\n
Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/a><\/p>\n\n\n\n
(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, Cisco<\/a>)<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"