Cisco Secure Firewall Management Center Software Cross-Site Scripting Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.1 Security Advisory

TL;DR 📌

A medium severity cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw could allow unauthenticated remote attackers to execute arbitrary scripts in the context of the interface. There are no workarounds available, but Cisco has released software updates to address this issue.

What happened 🕵️‍♂️

Cisco has reported a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This vulnerability arises from insufficient validation of user-supplied input, allowing attackers to execute arbitrary script code or access sensitive browser-based information through crafted input.

Affected products 🖥️

The vulnerability specifically affects Cisco Secure FMC Software. Cisco has confirmed that this issue does not impact Cisco Secure Firewall Adaptive Security Appliance (ASA) Software or Cisco Secure Firewall Threat Defense (FTD) Software.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 6.1, indicating a medium risk level. While it does not require authentication for exploitation, the potential for executing scripts could lead to unauthorized access to sensitive information. Organizations should prioritize applying the available updates to mitigate risks.

Fast facts ⚡

  • Vulnerability Type: Cross-Site Scripting (XSS)
  • CVSS Score: 6.1 (Medium)
  • Exploitability: Unauthenticated remote access
  • Workarounds: None available
  • Affected Product: Cisco Secure FMC Software

For leadership 🧭

Executive summary. Cisco’s Secure Firewall Management Center admin interface can be manipulated by an outside attacker to run malicious script in an administrator’s browser, without needing valid credentials first. With no workaround available, patching is the only fix and should be scheduled promptly given FMC’s role managing firewall policy.

Why it matters:

  • The flaw sits in the web-based management interface of FMC, the console used to configure and monitor Cisco firewalls, so a compromised session there could expose control over firewall policy.
  • No authentication is required to attempt exploitation, widening the pool of potential attackers to anyone who can reach the management interface.
  • There are no workarounds, so affected FMC deployments remain exposed until the software update is applied.
  • ASA and FTD are explicitly unaffected, so the exposure is limited to FMC instances specifically.

Now / Next / Later:

  • Now: Identify all Cisco Secure FMC instances and check whether their management interface is reachable from untrusted networks.
  • Next: Upgrade affected FMC deployments to the first fixed release identified by Cisco during the next available change window.
  • Later: Restrict access to the FMC management interface to trusted management networks only, and include FMC in routine patch-tracking cycles given the absence of workaround options for this class of issue.