Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-20439
Cisco Smart Licensing Utility
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .9709 99.9 YES
AFFECTED
Product Versions Fixed
Cisco Smart License Utility 2.1.0 – —
TIMELINE
Nov 8 Reserved by cisco
Sep 4 Published (CNA: cisco)
Mar 31 Added to CISA KEV, remediation due 2025-04-21
Description
A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential.
This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| November 8, 2023 | Reserved | Reserved by cisco |
| September 4, 2024 | Published | Published (CNA: cisco) |
| March 31, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-04-21 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Smart License Utility | — | 2.1.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-20439 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.