>> All posts

CVE-2024-20439: Cisco Smart Licensing Utility static-credential backdoor, actively exploited

The short version: Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential (CVE-2024-20439). An unauthenticated attacker who reaches an affected instance can simply log in with that built-in account and drive the CSLU API with admin rights. It scores 9.8, it's in CISA's KEV catalog, and it's being exploited in the wild. The fix is a version upgrade — there is no configuration workaround for a backdoor account. Steady hands, but move.

At a glance

FactDetail
Our severity takeHigh — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS (Cisco, CNA)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~91.9% · 99.8th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-04-21
Known exploited?Yes — added to KEV on evidence of active exploitation (often paired with CVE-2024-20440)
Vulnerability typeCWE-798 use of hardcoded credentials / CWE-912 hidden functionality → unauthenticated administrative access
Requires authenticated session?No — the static credential is the authentication
AffectedCisco Smart Licensing Utility 2.0.0, 2.1.0, 2.2.0 (only while the CSLU application is actively running)
Fixed inCisco Smart Licensing Utility 2.3.0 and later

What you need to know

CSLU is a small Windows application that helps manage smart-licensing for Cisco products without connecting each device directly to Cisco's cloud. In the affected releases, it ships with a built-in administrative account whose password is baked into the software — undocumented, and identical across every install.

That's the whole problem. An attacker doesn't guess or crack anything. Once they know the credential — and it has been recovered and published — they authenticate to the CSLU API as an administrator.

A couple of points worth keeping in view:

  • It's a hardcoded account, so there's no config you can toggle to close it. The only real remedy is upgrading to a build where the account is gone.
  • CSLU only listens while it's running. It isn't a service that's always up, which narrows the window compared with an always-on appliance — but "sometimes exposed" is still exposed, and it's being scanned for.
  • It travels with its sibling. CVE-2024-20440, an information-disclosure flaw in the same utility that leaks credentials from a debug log, has been observed used alongside this one.

How serious we see it

High — the 9.8 is fair.

Unauthenticated, network-reachable administrative access via a static credential is about as clean an attack as it gets: no chain, no exploit skill, just a login. It's in KEV, it's automatable, and the credential is public. The bounded, reassuring part is that it's narrow and fixable — it affects three specific CSLU releases, only while the utility is actually running, and a fixed build (2.3.0) exists. Confirming whether you run CSLU at all, and on which version, is quick.

Recommendations

Straight from Cisco's advisory (cisco-sa-cslu-7gHMzWmw) and CISA:

  1. Upgrade now. Move to Cisco Smart Licensing Utility 2.3.0 or later, which removes the static account. There is no workaround for a hardcoded credential.
  2. Confirm exposure first. Verify whether CSLU is installed anywhere, whether it's reachable from untrusted networks, and which version is running.
  3. Don't leave it listening. CSLU only needs to run when you're actively managing licenses — don't keep it up and internet-reachable.
  4. Hunt. If you ran an affected build, review CSLU and host logs for unexpected API activity and logins.
  5. If compromised, respond. Rotate any credentials or data the CSLU host could reach, and investigate for follow-on access.

How BreachRisk sees it

BreachRisk works from the outside in, the way an attacker does. Starting from little more than your domain, it discovers exposed Cisco licensing interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV and because our severity take reflects real-world impact.

That continuous, attacker's-eye view is the point: a licensing utility that quietly got stood up and left reachable is exactly the kind of asset that falls off an inventory — and exactly the kind BreachRisk maps before someone else logs in with the built-in account.

References

See your cyber risk, proven.