CVE-2024-20439Active Exploitation(cisco / smart_license_utility)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for cisco smart_license_utility systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-21. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-912CWE-798

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smart_license_utility

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Peaked 1d ago at 3 mentions (2026-05-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
smart_license_utility

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-03: 3Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-05-03: 1Exploit Tool / Code · 2026-05-03: 1Active Exploitation · 2026-05-03: 3Technical Details · 2026-05-03: 305-0309-30
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets5 URLs
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-20439 to the Known Exploited Vulnerabilities (KEV) catalog, signaling observed exploitation in the wild against Cisco Smart Licensing Utility CISA KEV. The KEV entry describes a static credential vulnerability that lets an unauthenticated,…

    Post summary

    CISA has listed CVE-2024-20439 in its KEV catalog, confirming that a static credential flaw in the Cisco Smart Licensing Utility is actively being exploited in the wild.

    1000077
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-20439: CISA adds Cisco Smart Licensing Utility static-credential flaw (CVE-2024-20439) to KEV; remote unauthenticated login yields admin credentials.

    Post summary

    CISA lists CVE‑2024‑20439 as a KEV, indicating active exploitation, and notes that attackers can obtain admin credentials via unauthenticated remote login.

    1000071
    152 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — VULNCHECK OBSERVES LIVE EXPLOITATION OF CRITICAL CISCO SMART LICENSING UTILITY FLAW September 30, 2026 PRODUCT: Cisco Smart Licensing Utility CVE: CVE-2024-20439 — CVSS 9.8 AFFECTED VERSIONS: 2.0.0 / 2.1.0 / 2.2.0 Fixed in 2.3.0 or later. IMPACT: An undocumented static administrative credential allows an unauthenticated remote attacker to log in to the CSLU API with administrative privileges. EXPLOITATION STATUS: CISA KEV Cisco previously observed exploitation attempts LIVE EXPLOITATION OBSERVED BY VULNCHECK CANARIES The flaw is exploitable only while Cisco Smart Licensing Utility is actively running. knownRansomwareCampaignUse: Unknown URGENT ACTION: Upgrade to 2.3.0 or later and investigate previously exposed/running instances for unexpected API or administrative activity. CONFIDENCE: VERY HIGH — Cisco + CISA KEV + VulnCheck Canary telemetry. SOURCE: https://vulncheck.com/ VENDOR: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-20439 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json #CyberSecurity #ThreatIntel #Cisco #CVE #ActiveExploitation #NetworkSecurity

    0000084
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-20439-smart-licensing-utility #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The research page announces an active exploit for CVE‑2024‑20439 in the Smart Licensing Utility, presenting PoC code and technical details, but does not mention a patch or workaround.

    0000022
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosmart_license_utility---

Explore more