March 31, 2025 · Applied Cybernetics Group
CVE-2024-20439 — Cisco Smart Licensing Utility
Cisco Smart Licensing Utility Static Credential Vulnerability
- Added to KEV
2025-03-31- Federal due date
2025-04-21- Vendor
- Cisco
- Product
- Smart Licensing Utility
- EPSS
- 99.5th percentile (score 0.871, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-20439
CISA short description
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.