← Back to home
wid-sec-w-2026-0964  ·  Published 2026-04-06  ·  View on BSI CERT-Bund ↗

Cisco Smart Software Manager On-Prem: Vulnerability allows Ausführen from beliebigem Programmcode with Administratorrechten

CVSS 9.8 CRITICAL

Risk Summary

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.

CVEs (1)

Affected Vendors

Cisco

Affected Products (2)

Cisco · Smart Software Manager On-Prem <9-202601
Cisco · Smart Software Manager On-Prem 9-202601

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more