Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerabilitynew
Cisco fixed an unauthenticated Java deserialization RCE in FMC's External Database Access feature allowing root command execution via a TCP port.
Insecure deserialization of a user-supplied Java byte stream in Cisco Secure Firewall Management Center's External Database Access feature lets an unauthenticated remote attacker execute arbitrary commands and elevate to root. Exploitation requires sending a crafted serialized stream to a specific TCP port from a host configured in the external database access list. Cisco has released software updates.
58