Cisco Secure Firewall Management Center Software Command Injection Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.9 Security Advisory

TL;DR 📌

A command injection vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows authenticated attackers with Administrator-level privileges to execute arbitrary commands on the underlying operating system. The highest CVSS score for this vulnerability is 4.9, classified as Medium severity. No workarounds are available, and software updates have been released to address the issue.

What happened 🕵️‍♂️

A vulnerability in Cisco Secure Firewall Management Center Software could allow an authenticated remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability arises from insufficient input validation of certain HTTP request parameters sent to the web-based management interface. An attacker would need to authenticate and send a crafted HTTP request to exploit this vulnerability successfully.

Affected products 🖥️

The vulnerability affects Cisco Secure FMC Software if lockdown mode is enabled. Lockdown mode is disabled by default. Other products confirmed not to be vulnerable include:

  • Secure Firewall Adaptive Security Appliance (ASA) Software
  • Secure Firewall Threat Defense (FTD) Software
  • Secure IPS (formerly Next-Generation Intrusion Prevention System) Software

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

With a CVSS score of 4.9, this vulnerability is classified as Medium severity. The risk is primarily associated with authenticated access, as an attacker must have Administrator-level credentials to exploit the vulnerability. The potential impact includes unauthorized command execution on the affected device, which could compromise system integrity.

Fast facts ⚡

  • Vulnerability: Command Injection
  • CVSS Score: 4.9 (Medium)
  • Exploitation: Requires Administrator-level access
  • Workarounds: None available
  • Fixed Software: Updates released, specific versions not listed

For leadership 🧭

Executive summary. An administrator account on Secure Firewall Management Center could be used to break out to the underlying operating system, undermining the containment that lockdown mode is meant to provide. Exposure is limited to Administrator-level users, so this is a patch-cycle item rather than an emergency, but it should not be left indefinitely on internet-reachable management interfaces.

Why it matters:

  • The flaw sits in the FMC web management interface itself, so any Administrator account with access to that UI is a potential path to OS-level command execution on the appliance.
  • It specifically undermines lockdown mode, a control organisations enable to restrict what administrators can do on the underlying OS – this bug lets that restriction be bypassed via crafted HTTP requests.
  • Cisco confirms ASA, FTD and Secure IPS are not affected, so remediation effort can be focused solely on FMC deployments running with lockdown mode enabled.
  • No workaround exists, so the only mitigation until upgrade is tightening who holds Administrator credentials and who can reach the FMC management interface.

Now / Next / Later:

  • Now: Identify every Secure Firewall Management Center instance with lockdown mode enabled and review who currently holds Administrator-level accounts on it.
  • Next: Upgrade affected FMC deployments to the first fixed release for their train during the next scheduled maintenance window, since no workaround is available.
  • Later: Restrict and audit Administrator-level access to the FMC web management interface on an ongoing basis, and factor lockdown-mode integrity into future FMC hardening reviews.