CVE-2024-20440: Cisco Smart Licensing Utility Information Disclosure Vulnerability
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20440?
CVE-2024-20440 has been classified with a high severity due to its potential to allow an unauthenticated remote attacker to access sensitive information.
How do I fix CVE-2024-20440?
To fix CVE-2024-20440, update the Cisco Smart Licensing Utility to a patched version that addresses the excessive verbosity in the debug log.
Which versions of Cisco Smart Licensing Utility are affected by CVE-2024-20440?
CVE-2024-20440 affects Cisco Smart Licensing Utility versions 2.0.0, 2.1.0, and 2.2.0.
What type of information can be accessed through CVE-2024-20440?
CVE-2024-20440 could allow attackers to access sensitive information contained within the excessive debug log.
Can the exploitation of CVE-2024-20440 be mitigated?
Mitigation for CVE-2024-20440 includes implementing network security controls to limit access to the Cisco Smart Licensing Utility.