← Vulnerability feed

Vulnerability record · CVE-2024-20440 · published 4 September 2024

CVE-2024-20440: Cisco Smart Licensing Utility debug log exposes credentials

Cisco · Smart License Utility

Cisco Smart Licensing Utility writes excessive detail into a debug log file, including credentials usable for API access. An unauthenticated remote attacker can retrieve those log files over HTTP, so the flaw leaks secrets rather than executing code.

7.5 CVSS 3.1 High EPSS 52% · top 1.1% CWE-532 · Sensitive information in log file
7.5CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated remote credential disclosure with a high EPSS score and no KEV listing warrants prompt patching and exposure reduction.

What it is

Cisco Smart Licensing Utility writes excessive detail into a debug log file, including credentials usable for API access. An unauthenticated remote attacker can retrieve those log files over HTTP, so the flaw leaks secrets rather than executing code.

Impact

An attacker gains sensitive log contents, including API credentials, enabling authenticated access to the utility's API and any data or actions that access permits.

Attack surface

Reachable over the network via a crafted HTTP request to the affected device; the CVSS vector shows no privileges and no user interaction required.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.52 (98.9th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the Cisco security advisory fix for Smart Licensing Utility as the first action.
  • Restrict network access to the utility's HTTP interface to trusted management networks.
  • Rotate any credentials that may have been written to debug logs or exposed via the API.
  • Disable or reduce debug-level logging where the product allows it.
  • Monitor for unexpected requests to log or debug endpoints on the utility.

Detection

  • Review HTTP access logs for requests to log or debug file paths on Smart Licensing Utility hosts.
  • Alert on access to the utility from untrusted or unexpected source IPs.
  • Audit API authentication events for use of credentials that appear in log files.
  • Check for anomalous outbound or follow-on API activity from hosts running the utility.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20440 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2024-20440), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.