Information disclosure in Cisco Smart Licensing Utility - CVE-2024-20440
Published: September 4, 2024
Vulnerability identifier: #VU96801
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-20440
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to excessive data output by the API. A remote attacker can send a specially crafted HTTP request and obtain log files that contain sensitive data, including credentials that can be used to access the API.
Affected software
Cisco Smart Licensing Utility
How to mitigate CVE-2024-20440
Install updates from vendor's website.
Cisco Smart Licensing Utility - update to 2.3.0