Impact
A remote attacker can exploit the External Database Access feature of Cisco Secure Firewall Management Center (FMC) by sending a crafted, serialized Java byte stream to a listening TCP port. The deserialization flaw, identified as CWE‑502, allows arbitrary command execution with root privileges on the affected device, enabling a complete takeover of the system.
Affected Systems
Cisco Secure Firewall Management Center (FMC) software is affected. No specific software versions are listed in the available data, so any installed instance of this product remains potentially vulnerable until an official fix is applied. The vulnerability is only applicable to FMC deployments that have external database access configured.
Risk and Exploitability
The CVSS score of 9.8 indicates severe risk; however, the EPSS score of less than 1% suggests that exploitation attempts are currently very rare. The flaw is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to control a host that is on the FMC’s external database access list, meaning the attack surface is constrained to environments where the FMC is reachable from that host. If the management interface is not exposed to the public internet, the available attack surface diminishes further. The vulnerability is unauthenticated, so any host in the external database list can be used to launch the exploit.
OpenCVE Enrichment