Impact
A flaw in the web interface of Cisco Secure Firewall Management Center creates an improper system process at boot time, enabling an attacker to send crafted HTTP requests that bypass authentication and execute scripts with root privileges. This vulnerability is a CWE-288 improper authorization flaw, permitting an unauthenticated user to gain full control over the firewall device.
Affected Systems
The affected product is Cisco Secure Firewall Management Center (FMC) software. Specific version information is not provided in the available data.
Risk and Exploitability
The CVSS score of 10 and an EPSS score of <1% indicate a high severity but a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be the FMC web interface, which requires unauthenticated access and no special privileges. An attacker must craft HTTP requests to trigger the unintended authentication bypass and execute scripts with root privileges.
OpenCVE Enrichment