CVE-2024-20419
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including admi...
Affects 1 product across 1 vendor.
A critical vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) allows unauthenticated remote attackers to change any user's password, including administrative users, leading to full system compromise.
BSID: BS-2024-GLOBAL-160657-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-20419?
What is the CVSS score for CVE-2024-20419?
Is CVE-2024-20419 actively exploited?
How do I remediate CVE-2024-20419?
What systems are affected by CVE-2024-20419?
What NERC-CIP standard applies to CVE-2024-20419?
What IEC 62443 requirement maps to CVE-2024-20419?
| CVE ID | CVE-2024-20419 |
|---|---|
| BSID | BS-2024-GLOBAL-160657-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-07-17 |
| Last Modified | 2026-06-17 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.
Source: NIST NVD / MITRE CVE Database
The vulnerability is due to improper implementation of the password-change process. An attacker can exploit this by sending crafted HTTP requests to the affected device, gaining access to the web UI or API with the privileges of the compromised user.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Affected Versions |
|---|---|---|
| Cisco | Smart Software Manager On-Prem | < 8-202112 |
| CISA known-exploited | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
Implement strict access controls and monitor for unusual password change activities. Use multi-factor authentication (MFA) for all administrative accounts.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which can compromise the security of the electronic security perimeter.
This CVE maps to SR 7.6 as it involves a vulnerability in the authentication mechanism, which can lead to unauthorized access and control of the system.
Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.
AI Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 1ea54cdecb862e8b374e8c22e1541a912cee1d9e8f9de8b9926960fd8dbaa998ad7ed30c1f8d93290239fa4749873bb445ff38604aaacb0d956e56f883f19d34 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →