Cisco FMC static credential vulnerability exploited as a zero-day

Cisco has issued a security advisory regarding a zero-day vulnerability in its Secure Firewall Management Center (FMC) caused by static credentials. The flaw allows unauthenticated remote attackers to access sensitive data, and Cisco has released patches to address the issue.
Why it matters
This is a critical security vulnerability that exposes enterprise infrastructure to unauthorized access, necessitating immediate patching by system administrators.
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in