Executive brief
Cisco Secure Firewall Management Center (FMC) is a centralized management platform for Cisco firewall deployments. A vulnerability in its single sign-on system allows unauthenticated attackers to forge administrator credentials, gaining unauthorized access and potentially locking out legitimate administrators from management functions indefinitely.
Technical details
The vulnerability exists in the ASDM (Adaptive Security Device Manager) SSO token handler within Cisco Secure FMC Software, stemming from improper management and validation of SSO tokens. An unauthenticated, remote attacker can exploit this by performing session token forgery techniques to impersonate the ASDM administrator user without valid credentials. The attack has no preconditions (no authentication required) and is network-reachable. Successful exploitation grants full administrator access and enables attackers to prevent legitimate administrators from accessing the system through repeated login cycles. Cisco has released software patches to address this vulnerability, and no workarounds are available.
Affected products
- Cisco Secure Firewall Management Center Multiple versions (see Cisco advisory for specific affected releases)
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory cisco-sa-fmc2-multivulns-HXgcqRG published