CVE-2024-20419

CRITICAL ⚠ Exploit

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including admi...

Affects 1 product across 1 vendor.

BCS8.99
CVSS 3.110.0
EPSS80.6%
Percentile100th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-620: CWE-620
◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) allows unauthenticated remote attackers to change any user's password, including administrative users, leading to full system compromise.

BSID: BS-2024-GLOBAL-160657-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-20419?
A critical vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) allows unauthenticated remote attackers to change any user's password, including administrative users, leading to full system compromise.
What is the CVSS score for CVE-2024-20419?
CVE-2024-20419 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 80.6%.
Is CVE-2024-20419 actively exploited?
Public exploit available for CVE-2024-20419. Exploitation risk elevated.
How do I remediate CVE-2024-20419?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy PSIRT: [email protected]
What systems are affected by CVE-2024-20419?
CVE-2024-20419 affects: Cisco.
What NERC-CIP standard applies to CVE-2024-20419?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which can compromise the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2024-20419?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 as it involves a vulnerability in the authentication mechanism, which can lead to unauthorized access and control of the system.
Vulnerability Details
CVE IDCVE-2024-20419
BSIDBS-2024-GLOBAL-160657-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-07-17
Last Modified2026-06-17
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the password-change process. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access the web UI or API with the privileges of the compromised user.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is due to improper implementation of the password-change process. An attacker can exploit this by sending crafted HTTP requests to the affected device, gaining access to the web UI or API with the privileges of the compromised user.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Cisco Smart Software Manager On-Prem < 8-202112
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 810 Days
CISA known-exploitedNot in KEV catalog
Public Exploit⚠ Available — Reference
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict access controls and monitor for unusual password change activities. Use multi-factor authentication (MFA) for all administrative accounts.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the system, which can compromise the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 as it involves a vulnerability in the authentication mechanism, which can lead to unauthorized access and control of the system.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash1ea54cdecb862e8b374e8c22e1541a912cee1d9e8f9de8b9926960fd8dbaa998ad7ed30c1f8d93290239fa4749873bb445ff38604aaacb0d956e56f883f19d34
Related CVEs affecting Cisco
CVE-2018-0222 10.0 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allo... CVE-2022-20827 10.0 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV3... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2018-0101 10.0 A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Ci... CVE-2021-1388 10.0 A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO)...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →