Impact
Cisco ASDM’s single sign‑on handler for Secure Firewall Management Center is designed to validate session tokens, but when it fails to correctly manage the token, an attacker can forge a valid SSO token. This allows an unauthenticated user to authenticate as the ASDM administrator without provable credentials. The result is full administrative control of the firewall manager and the ability to lock out legitimate administrators by repeatedly re‑authenticating with forged tokens. The vulnerability is classified under CWE‑1259, reflecting insecure token management logic. Given the CVSS score of 8.2, the potential impact on confidentiality, integrity, and availability is high.
Affected Systems
The weakness affects Cisco Secure Firewall Management Center (FMC) software; the affected product is listed as "Cisco Secure Firewall Management Center". Specific version ranges are not disclosed in the advisory. Any deployment using the ASDM SSO feature is potentially impacted.
Risk and Exploitability
The EPSS score is stated as less than 1%, indicating that exploit attempts are currently rare, but the CVSS score shows high severity. The vulnerability is not listed in CISA’s KEV catalog, suggesting no large‑scale active exploitation has been reported. The attack vector is inferred to be a remote network-based attack against the ASDM SSO endpoint, requiring no local access or privileged credentials. Because the token forgery can be performed by any remote user, the practical risk remains significant for environments that rely on ASDM SSO for administrator access.
OpenCVE Enrichment