CVE-2024-20419 is a critical authentication vulnerability in Cisco Smart Software Manager On-Prem (including installations earlier than Release 7.0 that were previously known as Cisco Smart Software Manager Satellite). The flaw is caused by an improper implementation of the password-change process in the product’s authentication system. By sending crafted HTTP requests to an affected instance, an unauthenticated remote attacker can change the password of any local user account without knowing the existing password, including administrative accounts. After resetting a target account’s password, the attacker can authenticate to the web UI or API as that user. The issue affects vulnerable Cisco SSM On-Prem releases up to 8-202206 and is fixed in 8-202212; Release 9 is reported as not vulnerable.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module targeting Cisco Smart Software Manager (SSM) On-Prem (versions <= 8-202206) for CVE-2024-20419. The exploit leverages an improper access control vulnerability that allows an unauthenticated remote attacker to reset the password of any user, including administrative accounts. The module works by chaining several HTTP(S) requests to backend API endpoints: it first obtains a XSRF token and session, then generates an auth token for the target user, performs the password reset, and finally verifies successful authentication with the new password. The module is operational and provides full account takeover capabilities. The main endpoints targeted are '/backend/settings/oauth_adfs', '/backend/reset_password/generate_code', '/backend/reset_password', and '/backend/auth/identity/callback'. The code is written in Ruby and is structured as a standard Metasploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in Cisco Smart Software Manager On-Prem allowing password reset.
A critical authentication/password-change implementation flaw in Cisco Smart Software Manager On-Prem that allows a remote unauthenticated attacker to send a specially crafted HTTP request to change any user's password and gain unauthorized access, including full system compromise via administrator accounts.
Maximum-severity flaw in Cisco Smart Software Manager On-Prem that allows a remote, unauthenticated attacker to change passwords for arbitrary users (including admins) via crafted HTTP requests, enabling subsequent access to the web UI/API as the compromised user.
A critical authentication flaw in Cisco Smart Software Manager On-Prem (and earlier SSM Satellite) that allows unauthenticated remote attackers to change arbitrary users’ passwords via crafted HTTP requests, enabling subsequent access to the web UI/API as the compromised user.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.