Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewalls and security appliances. A vulnerability in its sftunnel inter-device communication protocol allows authenticated attackers with valid credentials to write arbitrary files executed as root, enabling complete compromise of the management system and all connected security devices.
Technical details
A CWE-862 (Improper Authorization) vulnerability exists in the sftunnel protocol where registered sftunnel peers have incorrect file write permissions, allowing them to write arbitrary files to any location on the device. An attacker can exploit this by either hijacking an sftunnel communication connection or leveraging valid sftunnel peer status to send a malicious sftunnel command that writes a file to disk. The file is subsequently executed with root privileges, achieving arbitrary code execution. The attacker must possess valid user credentials on the affected FMC device to exploit this vulnerability. Cisco has released software patches to address this issue; no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center See Cisco advisory for affected releases
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Cisco released software updates on the same date as disclosure