Impact
The vulnerability is caused by improper handling of the TLS certificate used in the sftunnel inter‑device communication protocol. An attacker who can connect to the sftunnel port with a crafted certificate can impersonate a peer device and become a registered sftunnel peer. The resulting compromise grants manager‑level access, which is equivalent to root, allowing the attacker full control over the device and its managed objects.
Affected Systems
Cisco Secure Firewall Management Center (FMC) and Cisco Secure Firewall Threat Defense (FTD) Software are affected. No specific version numbers are listed in the advisory, so any deployment of these products that has not been updated to the patched release is potentially vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.3 and an EPSS probability of less than 1%, indicating a high severity but a low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA KEV. The attack requires an adjacent, unauthenticated attacker with network access to the sftunnel interface; it succeeds only if the existing sftunnel connection is down or can be disrupted long enough for the attacker to introduce the forged certificate. Once exploited, the attacker gains full administrative privileges.
OpenCVE Enrichment