Two now-patched safety flaws impacting Cisco Sensible Licensing Utility are seeing energetic exploitation makes an attempt, in accordance with SANS Internet Storm Center.
The two critical-rated vulnerabilities in query are listed beneath –
- CVE-2024-20439 (CVSS rating: 9.8) – The presence of an undocumented static consumer credential for an administrative account that an attacker may exploit to log in to an affected system
- CVE-2024-20440 (CVSS rating: 9.8) – A vulnerability arising attributable to an excessively verbose debug log file that an attacker may exploit to entry such recordsdata by the use of a crafted HTTP request and procure credentials that can be utilized to entry the API
Profitable exploitation of the failings may allow an attacker to log in to the affected system with administrative privileges, and procure log recordsdata that include delicate knowledge, together with credentials that can be utilized to entry the API.
That mentioned, the vulnerabilities are solely exploitable in situations the place the utility is actively working.
The shortcomings, which influence variations 2.0.0, 2.1.0, and a pair of.2.0, have since been patched by Cisco in September 2024. Model 2.3.0 of Cisco Sensible License Utility isn’t prone to the 2 bugs.
As of March 2025, risk actors have been noticed trying to actively exploit the 2 vulnerabilities, SANS Know-how Institute’s Dean of Analysis Johannes B. Ullrich mentioned, including the unidentified risk actors are additionally weaponizing different flaws, together with what seems to be an data disclosure flaw (CVE-2024-0305, CVSS rating: 5.3) in Guangzhou Yingke Digital Know-how Ncast.
It is at the moment not identified what the top objective of the marketing campaign is, or who’s behind it. In gentle of energetic abuse, it is crucial that customers apply the mandatory patches for optimum safety.
Source link