Threat actors have begun exploiting unpatched Cisco Smart Licensing Utility (CSLU) instances vulnerable to a recently disclosed backdoor admin account. The Windows-based CSLU application, which allows administrators to manage licenses on-premises without connecting to Cisco’s cloud services, contains two critical security flaws patched in September.
The primary vulnerability (CVE-2024-20439) involves an undocumented static admin credential that permits unauthenticated attackers to remotely access vulnerable systems with administrative privileges through the application’s API. Cisco simultaneously addressed a second critical flaw (CVE-2024-20440) that allows attackers to access sensitive log files containing API credentials via crafted HTTP requests.
Security researcher Nicholas Starke reverse-engineered the vulnerability approximately two weeks after Cisco’s patch release, publishing technical details including the decoded hardcoded password. This disclosure appears to have facilitated the current exploitation attempts.
Johannes Ullrich from SANS Technology Institute has confirmed that attackers are now chaining these two vulnerabilities to target internet-exposed CSLU instances. While the attackers’ ultimate objectives remain unclear, they are also attempting to exploit other vulnerabilities, including an information disclosure flaw affecting Guangzhou Yingke Electronic DVRs.
Despite ongoing exploitation, Cisco’s Product Security Incident Response Team maintains they have found no evidence of attacks leveraging these vulnerabilities. This isn’t Cisco’s first experience with backdoor accounts, as similar hardcoded credentials have previously been discovered in several company products including DNA Center, IOS XE, WAAS, and Emergency Responder software.
The vulnerabilities only affect systems running vulnerable CSLU releases and are exploitable only when the application is actively running, as it’s not designed to operate in the background by default.
