Security researchers at SANS Internet Storm Center have reported active exploitation attempts targeting two recently patched critical vulnerabilities in Cisco Smart Licensing Utility.
## Critical Vulnerabilities
The two vulnerabilities, both rated with a critical CVSS score of 9.8, include:
– **CVE-2024-20439**: An undocumented static user credential for an administrative account that allows attackers to log in to affected systems
– **CVE-2024-20440**: Excessively verbose debug log files that can be accessed via crafted HTTP requests, exposing credentials for API access
Successful exploitation grants attackers administrative access to affected systems and enables them to obtain sensitive data, including API credentials. However, exploitation is only possible when the utility is actively running.
## Affected Versions and Patches
The vulnerabilities impact Cisco Smart License Utility versions 2.0.0, 2.1.0, and 2.2.0. Cisco released patches in September 2024, and version 2.3.0 is not affected by these issues.
## Ongoing Campaign
As of March 2025, threat actors have been observed actively exploiting these vulnerabilities. According to Johannes B. Ullrich, Dean of Research at SANS Technology Institute, the attackers are also targeting other vulnerabilities, including an information disclosure flaw (CVE-2024-0305, CVSS score: 5.3) in Guangzhou Yingke Electronic Technology Ncast.
The campaign’s objectives and attribution remain unknown. Users are strongly advised to apply available patches immediately to protect their systems.
