Authentication Bypass in Cisco Secure FMC Software Management Interface
CVE-2025-20301
What is CVE-2025-20301?
An issue has been identified in the web-based management interface of Cisco Secure FMC Software that may allow an authenticated, low-privileged, remote attacker to access troubleshoot files belonging to a different domain. This occurs due to missing authorization checks within the system. By exploiting this gap, an attacker can directly request and obtain sensitive troubleshoot files from another managed domain within the same Cisco Secure FMC instance, potentially exposing critical information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower Management Center 6.2.3.12
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.10
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved