Executive brief
Cisco Secure Firewall Management Center (FMC) is a web-based administrative console used to manage firewall and threat defense devices across an organization. A SQL injection vulnerability in the management interface allows authenticated administrators with certain roles to execute arbitrary database queries, potentially exposing sensitive data and compromising the security of all managed devices. An attacker with valid administrative credentials could extract sensitive information, steal session credentials, and take actions with full administrative privileges.
Technical details
This SQL injection vulnerability in Cisco Secure FMC Software's web-based management interface stems from insufficient validation of user-supplied input in database queries. The vulnerability is network-reachable and requires authentication with specific elevated roles (Security Approver, Access Admin, or Network Admin). An attacker can exploit this by sending a crafted HTTP request to the affected web interface, allowing them to obtain arbitrary data from the database, retrieve session credentials of authenticated administrators, and execute administrative actions on the affected device. The CVSS v3.1 base score is 8.8 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating a high-severity vulnerability with network attack vector and high privilege requirements.
Affected products
- Cisco Secure Firewall Management Center Software See vendor advisory for affected versions
Timeline
- 2026-09-16: disclosed
- 2026-09-16: advisory: Cisco Security Advisory cisco-sa-fmc-mulivulns-4PsnFwvx published