Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A vulnerability in Cisco Secure Firewall Management Center (FMC) web interface allows unauthenticated remote attackers to log in using a static low-privileged account. The vulnerability exists due to hardcoded credentials for a low-privileged user account. Attackers can use this account to access sensitive management data, network policies, and firewall configurations. This vulnerability is particularly dangerous when combined with other FMC vulnerabilities, as it can be chained to achieve privilege escalation and administrative access to the FMC system. If the FMC management interface is not exposed to the public internet, attack surface is reduced.
- Network access to the FMC web interface (typically port 443/HTTPS)
- FMC management interface accessible from the attacker's network
Patching may require device reboot — plan for process interruption
/api/v1/advisories/18d51b20-a76c-4101-a532-20ec490691fcGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.