Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability

🚨 SEVERITY: CRITICAL — CVSS 10.0 Security Advisory

TL;DR 📌

A critical vulnerability has been identified in the Cisco Secure Firewall Management Center (FMC) Software that allows unauthenticated remote code execution via the RADIUS subsystem. This vulnerability has a CVSS score of 10.0, indicating a severe risk. Immediate action is required to patch affected systems.

What happened 🕵️‍♂️

A vulnerability in the RADIUS subsystem of Cisco Secure FMC Software could allow an unauthenticated, remote attacker to execute arbitrary shell commands on the device. This issue arises from improper handling of user input during the authentication phase. Exploitation requires that RADIUS authentication is configured for the web-based management interface, SSH management, or both.

Affected products 🖥️

The vulnerability affects Cisco Secure FMC Software releases 7.0.7 and 7.7.0 if RADIUS authentication is enabled.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no effective workarounds for this vulnerability. However, organizations can mitigate risk by using alternative authentication methods, such as local user accounts, external LDAP authentication, or SAML single sign-on (SSO). It is crucial to evaluate the applicability and impact of these alternatives in your environment.

Risk in context 🎯

Given the critical nature of this vulnerability (CVSS 10.0), the risk is high, especially for organizations using RADIUS authentication. An attacker could gain complete control over affected devices, leading to potential data breaches or service disruptions.

Fast facts ⚡

  • Vulnerability: RADIUS Remote Code Execution
  • CVSS Score: 10.0 (Critical)
  • Affected Software: Cisco Secure FMC Software 7.0.7 and 7.7.0 with RADIUS enabled
  • Exploitation: Requires RADIUS authentication configuration
  • Workarounds: None available; alternative authentication methods recommended

For leadership 🧭

Executive summary. Any FMC appliance using RADIUS for admin login on its web console or SSH can be fully taken over by a remote, unauthenticated attacker, with a maximum CVSS score of 10.0. Because FMC manages firewall policy across an estate, this needs emergency patching or reconfiguration now, not at the next scheduled window.

Why it matters:

  • FMC is the central management point for Cisco firewalls, so command execution on it can extend to control over the policies protecting the wider network.
  • The flaw sits in how user input is handled during RADIUS authentication, meaning no valid credentials are needed to trigger it.
  • Affects both the web-based management interface and SSH management if either uses RADIUS, widening the exposed attack surface.
  • There is no workaround that leaves RADIUS in place; the only mitigation is switching authentication method entirely.

Now / Next / Later:

  • Now: Identify every Cisco Secure FMC instance on releases 7.0.7 or 7.7.0 and check whether RADIUS authentication is enabled for web or SSH management.
  • Next: Patch to the first fixed release for your train during an emergency or next available change window, or switch affected instances to local accounts, LDAP, or SAML SSO if patching must wait.
  • Later: Review authentication configuration standards for management platforms so RADIUS is not the default choice for internet- or network-reachable admin interfaces without compensating controls.