Description
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user.

This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authentication Bypass – Administrator Access
Action: Immediate Patch
AI Analysis

Impact

Cisco ASDM’s single sign‑on handler for Secure Firewall Management Center is designed to validate session tokens, but when it fails to correctly manage the token, an attacker can forge a valid SSO token. This allows an unauthenticated user to authenticate as the ASDM administrator without provable credentials. The result is full administrative control of the firewall manager and the ability to lock out legitimate administrators by repeatedly re‑authenticating with forged tokens. The vulnerability is classified under CWE‑1259, reflecting insecure token management logic. Given the CVSS score of 8.2, the potential impact on confidentiality, integrity, and availability is high.

Affected Systems

The weakness affects Cisco Secure Firewall Management Center (FMC) software; the affected product is listed as "Cisco Secure Firewall Management Center". Specific version ranges are not disclosed in the advisory. Any deployment using the ASDM SSO feature is potentially impacted.

Risk and Exploitability

The EPSS score is stated as less than 1%, indicating that exploit attempts are currently rare, but the CVSS score shows high severity. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale active exploitation has been reported. The attack vector is inferred to be a remote network-based attack against the ASDM SSO endpoint, requiring no local access or privileged credentials. Because the token forgery can be performed by any remote user, the practical risk remains significant for environments that rely on ASDM SSO for administrator access.

Generated by OpenCVE AI on September 17, 2026 at 21:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco update that addresses the ASDM SSO token handling flaw
  • If a patch is unavailable, temporarily disable ASDM SSO or force credential re‑authentication to prevent token forgery
  • Restrict network access to the ASDM management interface, for example by placing it behind a VPN or firewall rule that limits connections to trusted hosts
  • Monitor security logs for repeated ASDM login attempts and consider alerting on anomalous token usage patterns

Generated by OpenCVE AI on September 17, 2026 at 21:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Firewall Management Center
Vendors & Products Cisco
Cisco secure Firewall Management Center

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely.
Title Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability
Weaknesses CWE-1259
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Cisco Secure Firewall Management Center
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T14:18:37.481Z

Reserved: 2026-08-19T12:02:03.633Z

Link: CVE-2026-76413

cve-icon Vulnrichment

Updated: 2026-09-17T14:18:33.661Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:13.840

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-76413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-1259

    Improper Restriction of Security Token Assignment