← Back to browse · API

CVE-2024-20419

Severity
CRITICAL
CVSS
10.0
EPSS
0.80635
Risk score
68.22
CISA KEV
No
PoC
No
Published
2024-07-17
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-18134, GHSA-5697-P67M-73P6
Products
Cisco:Cisco Smart Software Manager On-Prem 8-202206
Sources
euvd EUVD-2024-18134

Description

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.

References