Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Act NowCVSS 5.3cisco-sa-fmc-static-cred-BET3CjhJul 29, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in Cisco Secure Firewall Management Center (FMC) web interface allows unauthenticated remote attackers to log in using a static low-privileged account. The vulnerability exists due to hardcoded credentials for a low-privileged user account. Attackers can use this account to access sensitive management data, network policies, and firewall configurations. This vulnerability is particularly dangerous when combined with other FMC vulnerabilities, as it can be chained to achieve privilege escalation and administrative access to the FMC system. If the FMC management interface is not exposed to the public internet, attack surface is reduced.

What this means
What could happen
An attacker can remotely log in to your Firewall Management Center using a static low-privileged account without any credentials and access sensitive configuration data and network security policies that the FMC controls.
Who's at risk
Network security teams and IT operations staff who manage Cisco Secure Firewall Management Center appliances. FMC is used to centrally manage and monitor Cisco firewalls and security appliances across organizations, making it a critical control point for network security policy.
How it could be exploited
An attacker can access your FMC web interface over the network and log in using a hardcoded low-privileged account name without needing a password. Once logged in, the attacker gains visibility into your firewall configurations, security policies, and other sensitive settings managed by the FMC. This can be combined with other vulnerabilities in the FMC to escalate privileges to administrative access.
Prerequisites
  • Network access to the FMC web interface (typically port 443/HTTPS)
  • FMC management interface accessible from the attacker's network
remotely exploitableno authentication requiredactively exploited (KEV)low complexityaffects security control systemlow CVSS score (5.3) but high SIR due to privilege escalation chain
Exploitability
Actively exploited — confirmed by CISA KEV
Affected products (1)
ProductAffected VersionsFix Status
Secure Firewall Management Center (FMC) AppliancesAll versionsFix available
Remediation & Mitigation
0/3
Do now
0/2
HOTFIXUpdate Secure Firewall Management Center to a version that patches the static credential vulnerability
WORKAROUNDRestrict network access to the FMC management interface to trusted administrative networks only using firewall rules or network segmentation
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGImplement strong authentication controls such as MFA on the FMC management interface
API: /api/v1/advisories/18d51b20-a76c-4101-a532-20ec490691fc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.