CVE-2026-20323
largeCisco Secure FMC/FTD sftunnel TLS flaw lets adjacent attacker gain root-level access
CVE-2026-20323 is an improper certificate validation flaw (CWE-295) in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software, arising from improper management of the TLS certificate used for the sftunnel management connection. An unauthenticated, adjacent attacker can trigger it by connecting to the sftunnel port with a crafted TLS certificate, but the attack succeeds only if the sftunnel connection is already down or if the attacker can disrupt it long enough to complete the impersonation. A successful exploit lets the attacker register as the sftunnel peer and obtain manager-role access, which is equivalent to root on the device. Any organization running a paired Cisco Secure FMC/FTD deployment is potentially affected, though exploitation requires network adjacency to the sftunnel channel. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and exploitation has not been reported in the wild.
What to do: Upgrade both Secure FMC and Secure FTD to the fixed releases identified in Cisco's security advisory (version numbers are not specified in this dataset). Until patched, restrict access to the sftunnel management port via ACLs so only the legitimate FMC/FTD peers can reach it, and monitor for sftunnel connection drops or unexpected peer registrations, since exploitation depends on the tunnel being down or disruptable.
| Cisco Secure Firewall Management Center (FMC) Software | — |
| Cisco Secure Firewall Threat Defense (FTD) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate. A successful exploit could allow the attacker to become a registered sftunnel peer with root access. Note: The attack is successful only if the sftunnel connection is down or the attack can disrupt the sftunnel connection long enough to execute the attack.
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.