Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Cisco License On-Prem's web management could let an attacker reset any user's password, potentially granting them unauthorized administrative access. This is due to flaws in the password reset process and impacts systems managing software licenses.
- Attackers could reset any password, gaining access.
- This impacts critical license management systems.
- Confirm if Cisco License On-Prem is in use.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit a vulnerability in Cisco License On-Prem's password reset process. By sending a crafted request to the web interface, an attacker could reset the password for any account, potentially gaining administrative access and control over the application.
- Requires network access.
- Triggers via malicious request.
- Risk of unauthorized administrative access.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated, remote attacker could exploit this vulnerability by sending a malicious request to the web-based management interface of Cisco License On-Prem. This could allow the attacker to reset the password for any user account, including administrative ones, potentially granting them unauthorized access to the application with elevated privileges.
- Administrative access to the application.
- Malicious request to password reset.
- Unauthorized access and control.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem) web management interface is a likely target for unauthenticated remote attackers due to a password reset vulnerability. Infrastructure or platform teams managing this centralized licensing system should prioritize identifying all instances, assessing their network exposure, and confirming their business criticality to determine the appropriate response and engage accountable owners for remediation planning.
- Infrastructure or Platform Teams own the issue.
- Verify network exposure and business criticality.
- Plan remediation based on accountable owner risk.