CVE-2024-20419
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including adminis
Description
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Weakness: CWE-620
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Smart Software Manager On-Prem | Network & Security Management | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco Smart Software Manager On-Prem
- cisco · smart_software_manager_on-prem
Vendor advisory
Cisco Smart Software Manager On-Prem Password Change Vulnerability
Cisco’s rating: Critical (advisory CVSS 10.0) · Published Jul 17, 2024 · updated Aug 7, 2024 (revision 1.1)
Bug ID: CSCwk21399
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from