Impact
A SQL injection flaw exists in the web-based management interface of Cisco Secure Firewall Management Center software. The application fails to properly validate user-supplied input, enabling an attacker who is authenticated with a Security Approver, Access Admin, or Network Admin role to send a crafted HTTP request that injects SQL commands. The successful exploitation grants the attacker unrestricted read access to the database, the ability to extract session credentials of authenticated administrators, and the power to perform any administrative actions on the device. The weakness is identified as CWE-89, which signifies a classic injection vulnerability that bypasses intended access controls.
Affected Systems
The vulnerability affects Cisco Secure Firewall Management Center (FMC) devices. No specific firmware or software version ranges are supplied in the advisory, so all installations of FMC are potential targets until an official fix is published. Users must verify the presence or absence of the issue by consulting Cisco’s patch notes for their installed FMC version.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is below 1%, suggesting that exploitation is currently considered uncommon, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the attack requires only an account with common administrative roles and uses a standard web interface, a sufficiently motivated attacker can mount the exploit. The risk to an organization therefore remains significant, especially if privileged accounts are not tightly controlled or if the device is exposed to untrusted networks.
OpenCVE Enrichment