Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerabilities

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

Multiple vulnerabilities have been identified in the Cisco Secure Firewall Management Center (FMC) Software that could allow authenticated, low-privileged remote attackers to access unauthorized files. The highest CVSS score for these vulnerabilities is 6.5, indicating a medium level of risk. Software updates are available to address these issues, but there are no workarounds.

What happened 🕵️‍♂️

Cisco has disclosed multiple vulnerabilities in the web-based management interface of the Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities could allow an authenticated, low-privileged remote attacker to access files they are not authorized to view, including troubleshoot files and generated reports from different domains managed on the same FMC instance. The vulnerabilities stem from missing authorization checks.

Affected products 🖥️

The vulnerabilities affect Cisco Secure FMC Software when configured for multitenancy using domains. Other Cisco products, such as the Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, are confirmed not to be vulnerable.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate these vulnerabilities.

Risk in context 🎯

The highest CVSS score for these vulnerabilities is 6.5, which is categorized as Medium. The vulnerabilities are accessible over the network (internet-facing) and require authentication, but they do not impact availability. Successful exploitation could lead to unauthorized access to sensitive information, which could have serious implications for data privacy and security.

Fast facts ⚡

  • Vulnerabilities: Authorization bypass in Cisco Secure FMC Software
  • CVSS Score: 6.5 (Medium)
  • Exploitation: Requires authenticated access
  • Impact: Unauthorized access to sensitive files
  • Workarounds: None available

For leadership 🧭

Executive summary. Any organisation running multitenant FMC deployments should assume that low-privileged accounts in one domain could read troubleshooting data and reports from other domains on the same box. There is no workaround, so this needs scheduling into a proper patch window rather than urgent emergency action.

Why it matters:

  • Affects Cisco Secure FMC specifically when configured for multitenancy using domains, a common setup for managed security providers and large enterprises separating customers or business units on one management platform
  • An authenticated but low-privileged user in one domain can pull troubleshoot files and generated reports from other domains they should not have visibility into, breaking the tenant isolation the platform is meant to provide
  • No workaround exists, so exposure persists until the fixed release is installed
  • ASA and FTD are confirmed unaffected, so the fix effort is contained to FMC instances rather than the wider firewall estate

Now / Next / Later:

  • Now: Identify every FMC instance configured for multitenancy with domains and review who holds low-privileged accounts on them, since any of those users could currently pull cross-domain troubleshoot files and reports.
  • Next: Schedule an upgrade to the first fixed release for your FMC train during the next change window, as no workaround is available to reduce risk in the meantime.
  • Later: Build FMC version tracking into routine patch cycles and periodically audit domain-scoped account privileges so cross-domain data exposure is caught even when no workaround exists to fall back on.