Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for enterprise firewalls. A SQL injection vulnerability in its web-based management interface allows authenticated users to bypass database security controls, potentially exposing sensitive firewall configurations, access policies, and operational data. An attacker with valid credentials could read or modify the entire database and access files on the underlying system.
Technical details
This is a SQL injection vulnerability (CWE-89) in the web-based management interface of Cisco Secure FMC Software, caused by inadequate validation of user-supplied input. The vulnerability requires valid user authentication to exploit; an attacker must send crafted requests to trigger the injection. A successful exploit grants full database access and allows reading certain files on the underlying operating system, potentially including sensitive configuration data and credentials. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center <UNKNOWN>
Timeline
- 2026-03-04: disclosed