VDB
CVE-2024-20440
CVE-2024-20440
PUBLISHED
CVSS 7.5 HIGH
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.
EPSS 51.90% · 98.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
51.90%
98.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | smart_license_utility | 2.0.0, 2.1.0, 2.2.0 |
| cisco | cisco_smart_license_utility | 2.1.0, 2.0.0, 2.2.0 |
| Cisco | Cisco Smart License Utility | 2.0.0, 2.1.0, 2.2.0 |
Timeline
- CVE Published
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 CrowdSec Sighting
- Jan 20, 1970 Nuclei Template
- Jan 20, 1970 Fix Commit
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
- Jan 21, 1970 CrowdSec Sighting
References
- Nuclei Template exploit
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-agent-dll-hj-Ptn7PtKe advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-20440 advisory