Cisco recently disclosed a critical flaw, rated 9.8 out of 10, in the SSM On-Prem component of its Smart Software Manager, a tool that helps organizations manage software and product activation keys. Cisco says the flaw, identified as CVE-2020-3158, could allow an attacker to gain access to a vulnerable part of the system with a highly privileged account. Additionally, the attacker does not need to have a valid login to “attack,” but could use a default, high-profile account to connect to the vulnerable system, gain read and write access to the system’s data, and change its settings.
The SSM On-Prem component is intended for Cisco customers who have specific and demanding security needs and do not want Cisco products to transmit data to a central SSM database over the Internet. Some customers may know it by its old name, “Cisco Smart Software Manager satellite”.
Steven Van Loo, an IT consultant and founder of Belgium-based IT consultancy hIQkru, found the default static password in SSM On-Prem on a system account that is outside the administrator’s control. Fortunately for Cisco customers around the world, the consultant reported the bug to Cisco, which fixed it with SSM On-Prem 7-202001, released in late January 2020. All devices running previous versions have the same static password.
However, it is not certain that a hacker would gain full administrator privileges by logging in with the static password, but could gain access to a vulnerable part of the system. SSM On-Prem systems are only vulnerable if high availability (HA) is enabled, as it is not a default setting.

Administrators can check if HA is enabled by looking at the web admin interface and checking the “high availability status” widget. If it is present, it means that the feature is enabled and the device is vulnerable. Administrators can also use the onprem console and type the ha_status command at the command prompt to determine the status of the device.
The SSM On-Prem flaw was the only significant issue disclosed in Cisco's February 2020 patch. The company has also disclosed six high-severity vulnerabilities affecting its Unified Contact Center, the firmware of its UCS C-Series Rack Servers, its Email Security Appliance and Security Management Appliance, and its Data Center Network Manager.
The flaw affecting Cisco UCS C-Series Rack Servers could allow a hacker to inject a malicious image into a device, provided they have physical access and are authenticated, allowing the individual to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot verification checks.
Finally, the bug affects the following Firepower Management Center and Secure Network Server products:
- Firepower Management Center (FMC) 2500
- Firepower Management Center (FMC) 4500
- Secure Network Server 3500 Series Appliances
- Secure Network Server 3600 Series Appliances
- Threat Grid 5504 Appliance
