Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account. The CSLU Windows application allows admins to manage licenses and linked products on-premises without connecting them to Cisco's cloud-based Smart Software Manager solution. Cisco patched this security flaw (tracked as CVE-2024-20439) in September, describing it as "an undocumented static user credential for an administrative account" that can let unauthenticated attackers log into unpatched systems remotely with admin privileges over the API of the CSLU app. The company also addressed a second critical CLSU information disclosure vulnerability (CVE-2024-20440) that unauthenticated attackers can use to access log files containing sensitive data (including API credentials) by sending crafted HTTP requests to vulnerable devices. These two vulnerabilities only impact systems running vulnerable Cisco Smart Licensing Utility releases and are only exploitable if the user starts the CSLU app—which isn't designed to run in the background by default. Aruba threat researcher Nicholas Starke reverse-engineered the vulnerability and published a write-up with technical details (including the decoded hardcoded static password) roughly two weeks after Cisco released security patches. SANS Technology Institute's Dean of Research Johannes Ullrich reported that threat actors are now chaining the two security flaws in exploitation attempt...
Critical Cisco Smart Licensing Utility flaws now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Mar 20, 2025
·Updated
Affected Software
3 affected components
Cisco Smart Licensing Utility
Guangzhou Yingke Electronic DVRs
Cisco Smart Licensing Utility
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in the Cisco Smart Licensing Utility that are being actively exploited by attackers.
2
What security implications are discussed?
The article highlights the risk posed by an unpatched vulnerability that exposes a built-in backdoor admin account in the Cisco Smart Licensing Utility.
3
What products or software are affected?
The main software affected is the Cisco Smart Licensing Utility, along with potential impacts on Guangzhou Yingke Electronic DVRs.
4
Who is affected by these vulnerabilities?
Organizations using unpatched versions of Cisco Smart Licensing Utility are at risk of being targeted by attackers.
5
What should users do to protect themselves from these vulnerabilities?
Users should promptly apply patches released by Cisco to protect against the vulnerabilities in the Smart Licensing Utility.