← Back to browse · API

CVE-2024-20440

Severity
HIGH
CVSS
7.5
EPSS
0.51897
Risk score
48.16
CISA KEV
No
PoC
No
Published
2024-09-04
Modified
2025-04-01
First seen
2026-08-07
Aliases
EUVD-2024-18155, GHSA-G9J7-W55P-JQ3W
Products
Cisco:Cisco Smart License Utility 2.0.0, Cisco:Cisco Smart License Utility 2.1.0, Cisco:Cisco Smart License Utility 2.2.0
Sources
euvd EUVD-2024-18155

Description

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

References