CVE-2024-20419 | Critical Cisco SSM Vulnerability

Share This Post

CVSS 3.1 : 10 | Critical

Cisco has just released a patch to mitigate an emerging vulnerability in Cisco’s Smart Software Manager (SSM) On-Prem systems that allows an unauthenticated remote attacker to change administrative accounts’ passwords and if successful, access the web UI or API with the privileges of the compromised user.

Currently there is no known activity of this exploit being utilized in the wild.

“This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.” – Cisco stated.

Sources:

Critical Cisco bug allows crims to change admin passwords • The Register

Cisco Smart Software Manager On-Prem Password Change Vulnerability

Cisco SSM On-Prem bug lets hackers change any user’s password (bleepingcomputer.com)

https://nvd.nist.gov/vuln/detail/CVE-2024-20419



Reach out to our incident response team for help

More To Explore

Information Security News – 6/22/26

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices Article Link: https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/ SQL Server 2025 AI Features Can Be Abused to Exfiltrate Sensitive Data Article

Information Security News – 6/15/26

Oracle PeopleSoft Servers Hacked in ShinyHunters Data Theft Attacks Article Link: https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/ Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code Article Link: https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.