A severe security flaw has been identified in Cisco’s Smart Software Manager On-Prem (SSM On-Prem), which exposes the system to the risk of unauthorized password alterations by remote attackers who do not need to authenticate.
This vulnerability arises from a flawed implementation of the password change procedure, creating notable security risks for Cisco users and IT professionals globally.
CVE-2024-20419 – Detailed Overview
The issue allows attackers to manipulate the system by sending specially crafted HTTP requests to vulnerable devices. If successful, this attack provides the intruder with access to the web interface or API at the same level as the compromised user, potentially leading to unauthorized access to sensitive data and critical system functions.
Affected systems include Cisco SSM On-Prem and Cisco Smart Software Manager Satellite (SSM Satellite), though the latter’s name was updated to reflect Release 7.0. The Cisco Smart Licensing Utility is not impacted by this vulnerability.
Cisco’s Response and Mitigation
Cisco has promptly addressed the vulnerability by releasing patches. Users are urged to apply these updates without delay as there are no available workarounds.
For detailed information and guidance, Cisco has issued an advisory available on their official security page. Those with service agreements should retrieve the security fixes through their regular update channels. It is essential for users to verify that their systems meet the requirements for the new release. For assistance, customers are encouraged to reach out to the Cisco Technical Assistance Center (TAC).
Affected Versions and Fixes
- Cisco SSM On-Prem Release | First Fixed Release
- 8-202206 and earlier | 8-202212
- 9 | Not affected
Customers who do not have service contracts or who acquired their systems from third-party vendors should contact Cisco TAC to obtain necessary updates. Having the product serial number and advisory URL at hand will expedite the process.
Cisco emphasizes that these security updates do not include new software licenses or additional features but specifically address the identified vulnerability. Users should regularly review Cisco’s security advisories to remain informed about potential risks and available solutions.



