ZeroHour

CVE-2026-20343

large

Unauthenticated API file download and DoS in Cisco Secure Firewall Management Center

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-20343 is a missing-authentication flaw (CWE-306) in a critical API of Cisco Secure Firewall Management Center (FMC) Software, the central management console for Cisco Secure Firewall (Firepower) devices. Because the API lacks authentication, an unauthenticated, remote attacker who can reach it can invoke it repeatedly to download files that should be restricted and consume unbounded disk space. A successful exploit can expose sensitive files and fill the FMC's disk until the device becomes unresponsive, causing a denial-of-service condition; the published CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) rates availability impact as High, even though the description also includes disclosure of sensitive files. Any organization running an affected FMC release is exposed, particularly where the FMC management interface is reachable from untrusted networks. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Upgrade FMC to the fixed release identified in Cisco's security advisory (fixed version numbers are not provided in the source data). Until patched, restrict access to the FMC management interface to trusted management networks or VPN only, verify whether the management port is internet-exposed, and monitor API access logs and disk utilization for signs of repeated unauthenticated calls or abnormal growth.

Affected
Cisco Secure Firewall Management Center (FMC) Software
Estimated exposure
largetens of thousands of FMC deployments worldwide (only a few thousand internet-exposed per public scans) — Cisco Secure Firewall/FTD is one of the most widely deployed enterprise firewall platforms and FMC is its standard central manager, implying an installed base on the order of tens of thousands of systems, while historical internet-wide…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be restricted and consume disk space so the device could become unresponsive, causing a DoS condition.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.