CVE-2026-20343
largeUnauthenticated API file download and DoS in Cisco Secure Firewall Management Center
CVE-2026-20343 is a missing-authentication flaw (CWE-306) in a critical API of Cisco Secure Firewall Management Center (FMC) Software, the central management console for Cisco Secure Firewall (Firepower) devices. Because the API lacks authentication, an unauthenticated, remote attacker who can reach it can invoke it repeatedly to download files that should be restricted and consume unbounded disk space. A successful exploit can expose sensitive files and fill the FMC's disk until the device becomes unresponsive, causing a denial-of-service condition; the published CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) rates availability impact as High, even though the description also includes disclosure of sensitive files. Any organization running an affected FMC release is exposed, particularly where the FMC management interface is reachable from untrusted networks. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Upgrade FMC to the fixed release identified in Cisco's security advisory (fixed version numbers are not provided in the source data). Until patched, restrict access to the FMC management interface to trusted management networks or VPN only, verify whether the management port is internet-exposed, and monitor API access logs and disk utilization for signs of repeated unauthenticated calls or abnormal growth.
| Cisco Secure Firewall Management Center (FMC) Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be restricted and consume disk space so the device could become unresponsive, causing a DoS condition.
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.