NCSC-NL said on Oct. 8 that Cisco fixed eight vulnerabilities in Cisco License On-Prem and Cisco Smart Software Manager On-Prem, including critical flaws in the web interface and API. The advisory covers both unauthenticated bugs and authenticated paths to higher-impact access.
The weak point is the management surface itself. Unauthenticated attackers can reset passwords, write files, or trigger denial of service, while authenticated admins can reach paths that allow root-level command execution and access to internal database content.
For anyone exposing this appliance on a management network, the issue is not just availability. A reachable instance sits in the control plane, so compromise can turn a licensing server into a foothold for credential, file, and system-control abuse.
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges.
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthoriz