Impact
Unsecured deserialization of data sent over the sftunnel inter‑device communication protocol allows an attacker who possesses valid administrative credentials on a managed FTD device to send crafted remote procedure calls. When processed, the vulnerability permits execution of arbitrary commands with the privileges of the running daemon, effectively granting root privileges on the device and its high‑availability peer. This type of flaw is classified as CWE‑502, insecure deserialization, which can lead to complete compromise of the affected appliance.
Affected Systems
Cisco Secure Firewall Management Center (FMC) installs that use the sftunnel protocol are affected. No specific version information was supplied in the CNA data, so all released FC‑secure versions should be assumed vulnerable until Cisco issues a patch.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical vulnerability; however, the EPSS score of less than 1 percent indicates a very low likelihood of exploitation in the wild at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been confirmed yet. Attackers must first authenticate as a valid administrator on a device that uses the sftunnel interface, which limits the threat to privileged insiders or attackers who have compromised an admin account. With those credentials, an attacker can remotely trigger the malicious RPCs and gain root-level access, allowing unrestricted modification or takeover of the device.
OpenCVE Enrichment