{"id":1588778,"date":"2025-03-21T05:15:44","date_gmt":"2025-03-21T07:15:44","guid":{"rendered":"https:\/\/teknomers.com\/fr\/les-cyberattaques-en-cours-exploitent-les-vulnerabilites-critiques-dans-cisco-smart-licensing-utility\/"},"modified":"2025-03-21T05:15:48","modified_gmt":"2025-03-21T07:15:48","slug":"les-cyberattaques-en-cours-exploitent-les-vulnerabilites-critiques-dans-cisco-smart-licensing-utility","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/les-cyberattaques-en-cours-exploitent-les-vulnerabilites-critiques-dans-cisco-smart-licensing-utility\/","title":{"rendered":"Les cyberattaques en cours exploitent les vuln\u00e9rabilit\u00e9s critiques dans Cisco Smart Licensing Utility"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">21 mars 2025<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><\/span><span class=\"p-tags\">Cyberattaque \/ vuln\u00e9rabilit\u00e9<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2025\/03\/Les-cyberattaques-en-cours-exploitent-les-vulnerabilites-critiques-dans-Cisco.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Selon Selon le Utility <a rel=\"noopener nofollow\" href=\"https:\/\/isc.sans.edu\/diary\/rss\/31782\" target=\"_blank\">SANS Centre d&#8217;orage Internet<\/a>.<\/p>\n<p>Les deux vuln\u00e9rabilit\u00e9s critiques en question sont \u00e9num\u00e9r\u00e9es ci-dessous &#8211; <\/p>\n<ul>\n<li><strong>CVE-2024-20439<\/strong> (Score CVSS: 9.8) &#8211; La pr\u00e9sence d&#8217;une information d&#8217;identification utilisateur statique sans papiers pour un compte administratif qu&#8217;un attaquant pourrait exploiter pour se connecter \u00e0 un syst\u00e8me affect\u00e9<\/li>\n<li><strong>CVE-2024-20440<\/strong> (Score CVSS: 9.8) &#8211; Une vuln\u00e9rabilit\u00e9 r\u00e9sultant d&#8217;un fichier journal de d\u00e9bogage excessivement verbeux qu&#8217;un attaquant pourrait exploiter pour acc\u00e9der \u00e0 ces fichiers au moyen d&#8217;une demande HTTP fabriqu\u00e9e et obtenir des informations d&#8217;identification qui peuvent \u00eatre utilis\u00e9es pour acc\u00e9der \u00e0 l&#8217;API<\/li>\n<\/ul>\n<p>L&#8217;exploitation r\u00e9ussie des d\u00e9fauts pourrait permettre \u00e0 un attaquant de se connecter au syst\u00e8me affect\u00e9 avec des privil\u00e8ges administratifs et d&#8217;obtenir des fichiers journaux contenant des donn\u00e9es sensibles, y compris des informations d&#8217;identification qui peuvent \u00eatre utilis\u00e9es pour acc\u00e9der \u00e0 l&#8217;API.<\/p>\n<div class=\"dog_two clear\"><center class=\"cf\"><a rel=\"nofollow noopener sponsored\" href=\"https:\/\/thehackernews.uk\/cis-securesuite\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybers\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2025\/03\/1740818990_705_Mozilla-met-a-jour-les-termes-de-Firefox-apres-le.png\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>Cela dit, les vuln\u00e9rabilit\u00e9s ne sont exploitables que dans les sc\u00e9narios o\u00f9 l&#8217;utilit\u00e9 fonctionne activement.<\/p>\n<p>Le <a rel=\"noopener nofollow\" href=\"https:\/\/starkeblog.com\/cve-wednesday\/cisco\/2024\/09\/20\/cve-wednesday-cve-2024-20439.html\" target=\"_blank\">lacunes<\/a>qui impact les versions 2.0.0, 2.1.0 et 2.2.0, ont depuis \u00e9t\u00e9 corrig\u00e9es par Cisco en septembre 2024. La version 2.3.0 de Cisco Smart License Utility n&#8217;est pas sensible aux deux bogues.<\/p>\n<p>En mars 2025, des acteurs de menace ont \u00e9t\u00e9 observ\u00e9s tentant d&#8217;exploiter activement les deux vuln\u00e9rabilit\u00e9s, a d\u00e9clar\u00e9 le doyen de la recherche de l&#8217;Institut de la technologie Sans Technology, Johannes B. Ullrich, ajoutant que les acteurs de menace non identifi\u00e9s armement \u00e9galement d&#8217;autres d\u00e9fauts, y compris ce qui semble \u00eatre une faille de divulgation d&#8217;informations (<a rel=\"noopener nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-0305\" target=\"_blank\">CVE-2024-0305<\/a>CVSS Score: 5.3) dans Guangzhou Yingke Electronic Technology Ncast.<\/p>\n<p>On ne sait actuellement pas quel est l&#8217;objectif final de la campagne, ni qui est derri\u00e8re. \u00c0 la lumi\u00e8re des abus actifs, il est imp\u00e9ratif que les utilisateurs appliquent les correctifs n\u00e9cessaires pour une protection optimale.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant? Suivez-nous <a rel=\"noopener nofollow\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Gazouillement <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"noopener nofollow\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">Liendin<\/a> Pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2025\/03\/ongoing-cyber-attacks-exploit-critical.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80221 mars 2025\ue804Ravie LakshmananCyberattaque \/ vuln\u00e9rabilit\u00e9 Selon Selon le Utility SANS Centre d&#8217;orage Internet. Les deux vuln\u00e9rabilit\u00e9s critiques en question sont \u00e9num\u00e9r\u00e9es ci-dessous &#8211; CVE-2024-20439 (Score CVSS: 9.8) &#8211; La pr\u00e9sence d&#8217;une information d&#8217;identification utilisateur statique sans papiers pour un compte administratif qu&#8217;un attaquant pourrait exploiter pour se connecter \u00e0 un syst\u00e8me affect\u00e9 CVE-2024-20440 (Score [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1588779,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[274266,274265,5859,4168,1297,5729,79002,274264,4161,274263,6124,429,8736,65,251584,274267,4160,238617,246491,4172,15001,79016,86278,4166,4164,12365],"class_list":["post-1588778","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actualites-de-piratage","tag-actualites-des-pirates","tag-cisco","tag-comment-pirater","tag-cours","tag-critiques","tag-cyber-security-news","tag-cyber-security-news-aujourdhui","tag-cyber-mises-a-jour","tag-cyber-nouvelles","tag-cyberattaques","tag-dans","tag-exploitent","tag-les","tag-licensing","tag-malware-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-securite-de-linformation","tag-securite-du-reseau","tag-securite-informatique","tag-smart","tag-the-hacker-news","tag-utility","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-vulnerabilites"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1588778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=1588778"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1588778\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/1588779"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=1588778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=1588778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=1588778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}