Vulnerability record · CVE-2024-20439 · published 4 September 2024
CVE-2024-20439: Cisco Smart Licensing Utility hard-coded admin credential allows remote login
Cisco · Smart License Utility
Cisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who knows or guesses this credential can log into the CSLU application API with administrative rights. Because the credential is static, it cannot be rotated by defenders and affects every deployment of the vulnerable utility.
Description
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote admin access via a static credential, listed in CISA KEV with a 99.8th percentile EPSS score.
What it is
Cisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who knows or guesses this credential can log into the CSLU application API with administrative rights. Because the credential is static, it cannot be rotated by defenders and affects every deployment of the vulnerable utility.
Impact
An attacker gains administrative access to the CSLU application API, allowing full control over the application's licensing functions and any data or configuration it manages. This is a complete compromise of confidentiality, integrity and availability of the CSLU application.
Attack surface
Reachable over the network via the CSLU application API with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed CSLU instance is a candidate target.
Exploitation
CVE-2024-20439 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2025-03-31) and has an EPSS 30-day probability of 0.92062 (99.8th percentile), indicating active exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented.
What to do
- Apply the Cisco security advisory fix for CSLU as the first action; consult cisco-sa-cslu-7gHMzWmw for the patched release.
- If a patch is not yet available, follow Cisco's mitigations or discontinue use of the product, per CISA BOD 22-01 guidance.
- Remove CSLU from direct internet exposure and restrict API access to trusted management networks only.
- Audit CSLU administrative accounts and logs for unexpected logins, and rotate any credentials that may have been exposed.
- Track CISA KEV remediation due date (2025-04-21) and confirm closure.
Detection
- Monitor CSLU application API authentication logs for successful logins from unexpected source IPs or at unusual times.
- Alert on use of the static administrative account or any login that does not map to a known, individually assigned administrator.
- Baseline normal CSLU API call patterns and flag anomalous administrative actions or configuration changes.
- Search network telemetry for external hosts reaching CSLU management ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-20439 to the Known Exploited Vulnerabilities catalog on 31 March 2025 as "Cisco Smart Licensing Utility Static Credential Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 21 April 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20439 | US Government Resource |
Track CVE-2024-20439 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-20439), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.