Cisco Raises Alarm on Critical Vulnerability Impacting On-Prem Smart Software Manager
Cisco has issued fixes to attend to a critical security vulnerability impacting Smart Software Manager On-Prem (Cisco SSM On-Prem) that has the potential to allow a remote, unauthenticated attacker to modify the password of any users, including those associated with administrative privileges.
The flaw, identified as CVE-2024-20419, comes with a CVSS rating of 10.0.
“This vulnerability stems from the incorrect implementation of the password-change procedure,” as stated in an advisory by the company. “By sending tailored HTTP requests to a vulnerable device, an attacker could exploit this vulnerability. A successful exploitation could grant an attacker access to the web UI or API using the compromised user’s privileges.”
This weakness impacts Cisco SSM On-Prem versions 8-202206 and earlier. The issue has been resolved in version 8-202212. It’s essential to note that version 9 is immune to this flaw.

CISA Introduces 3 Vulnerabilities to KEV Catalog
- CVE-2024-34102 (CVSS score: 9.8) – Adobe Commerce and Magento Open Source Incorrect Limitation of XML External Entity Reference (XXE) Vulnerability
- CVE-2024-28995 (CVSS score: 8.6) – SolarWinds Serv-U Path Traversal Vulnerability
- CVE-2022-22948 (CVSS score: 6.5) – VMware vCenter Server Inaccurate Default File Permissions Vulnerability
