cisco-sa-ssm-cli-execution-cHUcWuNrCriticalCVSS 9.8

Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability

Published
April 1, 2026
Last Modified
April 1, 2026

🔗 CVE IDs covered (1)

📋 Description

<p>A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.</p> <p>This vulnerability is due to the unintentional exposure of an&nbsp;internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with <em>root</em>-level privileges.</p> <p>Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.</p> <p>This advisory is available at the following link:<br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr</a></p>

🎯 Affected products1

  • Cisco Smart Software Manager On-Prem

🔗 References (2)