Impact
A specific file download API in Cisco Secure Firewall Management Center allows an authenticated remote attacker to download arbitrary files because user input is not sanitized. The attacker can send a crafted HTTPS request to the vulnerable endpoint. Successful exploitation leads to confidential data being exfiltrated from the affected system.
Affected Systems
The vulnerability affects Cisco Secure Firewall Management Center (FMC) software. No specific version range is listed in the advisory, so any version deployed in an environment remains potentially vulnerable until patched.
Risk and Exploitability
The CVSS v3.1 score is 7.7, indicating high severity. The EPSS score is below 1%, suggesting a low current exploitation probability. The vulnerability is not in the CISA KEV catalog, meaning no known active exploits are tracked. Exploitation requires valid credentials for a user with at least the Security Analyst role, but no elevated privileges are needed beyond authentication.
OpenCVE Enrichment