pwshub.com

Cisco's Smart Licensing Utility flaws suggest it's dumb

If you're running Cisco's supposedly Smart Licensing Utility, there are two flaws you ought to patch right now.

"Multiple vulnerabilities in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running," the networking giant warned about two critical issues.

"Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities."

The two independent flaws could allow a remote attacker to sign themselves in with admin privileges and subvert the whole system. That's bad if untrusted people or rogue users can reach the licensing service. If you have other defenses in front of the Cisco software, that'll mitigate the risk.

The vulnerabilities are:

  • CVE-2024-20439 - The flaw allows "an unauthenticated, remote attacker to log in to an affected system by using a static administrative credential," Cisco said. There's full admin access to be had for a cunning attacker.
  • CVE-2024-20440 - Cisco blames "excessive verbosity in a debug log file" for this bug, which allows a carefully designed HTTP request to "obtain log files that contain sensitive data, including credentials that can be used to access the API." In other words, game over, man (NSFW language.)

Both flaws have a CVSS rating of 9.8 out of 10 in severity and have no workaround. The networking biz has no further comment on the blunders.

A Cisco spokesperson told The Register, "These vulnerabilities are not exploitable unless the Cisco Smart Licensing Utility was started by a user and is actively running."

The vendor's Product Security Incident Response Team (PSIRT) "is not aware of any malicious use of these vulnerabilities, and fixed software is available," the spokesperson said.

  • Maximum-severity Cisco vulnerability allows attackers to change admin passwords
  • No rest for the wiry as Cisco Nexus switches flip out over latest zero-day
  • You had a year to patch this Veeam flaw – and now it's going to hurt some more
  • Microsoft squashes SmartScreen security bypass bug exploited in the wild

The issues were found internally by network security engineer Eric Vance, so hopefully, online crims haven't got around to exploiting them. But now that they are public, scumbags will pile in if they can find a vulnerable instance to attack, so patch now.

Also, as always, check your support license. "Customers may only download software for which they have a valid license, procured from Cisco directly, or through a Cisco authorized reseller or partner," it warns as a matter of course.

"In most cases this will be a maintenance upgrade to software that was previously purchased. Free security software updates do not entitle customers to a new software license, additional software feature sets, or major revision upgrades." ®

Source: theregister.com

Related stories
1 month ago - What kind of OS can be hijacked by clicking a link at just the right time? Microsoft's In this week's Patch Tuesday Microsoft alerted users to, among other vulnerabilities, a flaw in Windows Installer that can be exploited by malware or a...
1 month ago - The 'security issue' was caused by a 9.8-rated Magento flaw Adobe patched back in June Bad news for anyone who purchased a Cisco hoodie earlier this month: Suspected Russia-based attackers injected data-stealing JavaScript into the...
1 month ago - CISA wants you to leap on Citrix and Ivanti issues. Adobe, Intel, SAP also bid for patching priorities Patch Tuesday Another Patch Tuesday has dawned, as usual with the unpleasant news that there are pressing security weaknesses and...
1 week ago - Qualcomm has unveiled a new networking system with edge AI integration that the company says will reimagine how users experience their connected devices in the home.Read Entire Article
1 month ago - Get up to speed on the rapidly evolving world of AI with our roundup of the week's developments.
Other stories
51 minutes ago - It's organic, it's eco-friendly and it's affordable. Is there anything we don't like about the Awara Natural latex bed?
1 hour ago - Whether you travel often or will soon be traveling far, a travel pillow can make a huge difference in your comfort on the flight.
3 hours ago - Here's today's Connections answer and hints for groups. These clues will help you solve New York Times' popular puzzle game, Connections, every day!
3 hours ago - Here's today's Strands answers and hints. These clues will help you solve The New York Times' popular puzzle game, Strands, every day.
3 hours ago - Here's today's Connections answer and hints for groups. These clues will help you solve New York Times' popular puzzle game, Connections, every day!