CVE-2024-20440

High PUBLISHED

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This...

Cisco · Cisco Smart License Utility

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.5 High

At a Glance

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

nuclei_scanner
CVE Published
Sep 04, 2024
Exploitation Reported
Jan 25, 2026
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
cisco
cisco_smart_license_utility

2.1.0

Affected
cisco
cisco_smart_license_utility

2.0.0

Affected
cisco
cisco_smart_license_utility

2.2.0

Affected
Cisco
Cisco Smart License Utility

2.1.0

Affected
Cisco
Cisco Smart License Utility

2.0.0

Affected
Cisco
Cisco Smart License Utility

2.2.0

Affected

CVE References

  • cisco-sa-cslu-7gHMzWmw sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.