Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco warns of static low-privileged credentials in Secure Firewall Management Center's web interface, letting unauthenticated remote attackers log in and access sensitive data.
Cisco disclosed a vulnerability in the web interface of Secure Firewall Management Center (FMC) Software caused by the presence of static credentials for a low-privileged account. An unauthenticated remote attacker could log in to an affected device using the static account and access sensitive data within impacted systems. The attack surface is reduced when the FMC management interface does not have public internet access.
- Static credentials allow unauthenticated login to the FMC web interface
- Successful exploitation exposes sensitive data as a low-privileged user
- Exposure limited if the FMC management interface is not internet-facing
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.