>

Cisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week

In early October 2024, Cisco's disclosure cadence stacked two unrelated but equally urgent problems: CVE-2024-20419, a CVSS 10.0 unauthenticated password-change flaw in Smart Software Manager On-Prem that let anyone with network access reset the admin API account, and CVE-2024-20399, a CLI command-injection bug in NX-OS already being exploited in the wild per the CISA KEV catalog. This account reconstructs both flaws' mechanics, the patch timelines, and what this pairing says about authentication surface area in management tooling.

Continue ReadingCisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week
>