Cisco Secure Firewall Management Center Software XPATH Injection Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 4.9 Security Advisory

TL;DR 📌

A medium-severity XPATH injection vulnerability has been identified in the Cisco Secure Firewall Management Center (FMC) Software, allowing authenticated attackers to retrieve sensitive information. There are no workarounds available, and users are advised to apply the necessary software updates.

What happened 🕵️‍♂️

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software has been discovered. This vulnerability arises from insufficient input validation, enabling an authenticated remote attacker to send crafted requests to the management interface. Successful exploitation could lead to the retrieval of sensitive information from the affected device. Importantly, the attacker must possess valid administrative credentials to exploit this vulnerability.

Affected products 🖥️

The vulnerability affects Cisco Secure FMC Software when lockdown mode is enabled. Lockdown mode is disabled by default, which may limit exposure. Other Cisco products, such as Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software, are confirmed not to be vulnerable.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

With a CVSS score of 4.9, this vulnerability is classified as Medium severity. The exposure requires administrative credentials, which mitigates the risk somewhat. However, the potential for sensitive information retrieval makes it important for affected users to apply the necessary updates promptly.

Fast facts ⚡

  • Vulnerability: XPATH injection in Cisco Secure FMC Software
  • CVSS Score: 4.9 (Medium)
  • Exploitation: Requires valid administrative credentials
  • Workarounds: None available
  • Fixed Software: Updates released by Cisco

For leadership 🧭

Executive summary. This affects the management console for Cisco firewalls, not the firewalls themselves, and only comes into play where an admin account is compromised or misused and lockdown mode is enabled. Because lockdown mode is off by default and no exploitation is known, this can be scheduled as routine patching rather than an emergency.

Why it matters:

  • The flaw sits in the FMC web-based management interface, the console used to configure and monitor Cisco firewall deployments, so successful abuse exposes data from that management layer rather than from ASA or FTD firewalls themselves, which Cisco confirms are unaffected.
  • Exploitation requires valid administrative credentials, meaning the practical risk is tied to how well FMC admin accounts are protected, not to an unauthenticated network-facing attack surface.
  • The condition only applies when lockdown mode is enabled; since that mode is disabled by default, most default FMC installations are not exposed unless an organisation has deliberately turned it on.
  • There is no workaround, so organisations running FMC with lockdown mode enabled have no interim mitigation other than upgrading.

Now / Next / Later:

  • Now: Check whether lockdown mode is enabled on any Secure Firewall Management Center instances in your estate; if it is, treat patching as the priority action.
  • Next: During the next scheduled maintenance window, upgrade affected FMC deployments to the first fixed release identified for your software train.
  • Later: Build FMC software version and lockdown-mode configuration checks into routine firewall management audits so exposure to this class of issue is caught automatically in future.