Impact
A flaw in Cisco Secure FMC software allows an attacker who can authenticate with a user account of at least Security Analyst level (read‑only) to send a crafted HTTP payload to the web‑management interface. The server deserializes this user‑controlled data without proper validation, enabling the attacker to save the payload and then execute it on the underlying operating system with root privileges. The vulnerability is therefore a high‑severity root‑command execution risk that can compromise the entire FMC system and any connected network devices.
Affected Systems
The affected product is Cisco Secure Firewall Management Center, commonly known as FMC. No specific version range is listed in the advisory, so all deployed instances are potentially vulnerable until a patch is applied or the vulnerable feature is disabled.
Risk and Exploitability
The CVSS score of 8.8 indicates a high likelihood of successful exploitation if a valid credential is available. The EPSS score of less than 1% suggests a very low probability of observed exploitation at this time, and the vulnerability is not yet catalogued in the CISA KEV list. However, because the attack requires a legitimate user’s credentials, an internal threat actor or an attacker who has compromised an account can deploy the payload over the web interface, gain root access, and potentially compromise the entire network infrastructure. The existing weak deserialization mechanism is the root cause, and the attack vector is authenticated remote web‑based exploitation.
OpenCVE Enrichment