Identity

Active exploitation of Cisco Smart Licensing flaws underway

Many different letters, numbers and special symbols, and silhouette of key as symbol of password. Concept of strong password creating, password-protected data, information security

Threat actors have been ramping up intrusions leveraging a pair of critical Cisco Smart Licensing Utility vulnerabilities patched in September over the past week, Cybersecurity Dive reports.

Exploitation of the the static credential flaw, tracked as CVE-2024-20439, through the use of simple fixed passwords could facilitate the compromise of a log file exposed by the information disclosure bug, tracked as CVE-2024-20440, and eventual access of targeted devices, according to SANS Internet Storm Center's Johannes Ullrich, who remains uncertain of the success of the attempted exploitation. Malicious activity has been associated with a botnet with at least 10 bots facilitating scanning and attacks. "In addition to the Cisco vulnerabilities, this botnet also scans for exposed secrets. For example backup files like /backup.gz that are sometimes left behind by careless administrators. The bots that are part of this botnet have been scanning for a variety of vulnerabilities for a few weeks now," said Ullrich.

An In-Depth Guide to Identity

Get essential knowledge and practical strategies to fortify your identity security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds