Impact
The flaw resides in the initial configuration of the Apache JServ Protocol connector within Cisco Secure FMC. Because encryption parameters are not properly set during boot, an unauthenticated, remote attacker can send specially crafted packets to the AJP connector and convince it to act as a peer device. This is a CWE‑285 (Improper Authorization) weakness. This impersonation enables the attacker to execute commands with root privileges and take full control over the FMC REST APIs, leading to a complete compromise of the device.
Affected Systems
The issue affects Cisco Secure Firewall Management Center (FMC) software. No specific firmware or version range is listed in the advisory, so all current releases of FMC should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
Based on the description, it is inferred that the AJP connector must be exposed for the attack to be possible. The CVSS score of 9 indicates high severity. The EPSS score is below 1%, suggesting few observed exploits, and the vulnerability is not yet listed in CISA’s KEV catalog. However, the attack is possible over the network via the exposed AJP connector, and it requires the sftunnel link between FMC and FTD to be down. If that condition is met, the vulnerability can be exploited remotely without authentication, allowing execution of arbitrary code with root privileges. Therefore, the risk is significant for networks that expose the AJP endpoint and have an inactive sftunnel link.
OpenCVE Enrichment