Authorization Bypass in Cisco Secure FMC Management Interface
CVE-2025-20302
4.3MEDIUM
What is CVE-2025-20302?
A security flaw in the web-based management interface of Cisco Secure FMC Software allows low-privileged authenticated attackers to retrieve reports generated for different domains managed within the same Cisco Secure FMC instance. The vulnerability arises from missing authorization checks, enabling an attacker to access sensitive activity reports that are not meant for their domain. This could lead to unauthorized disclosure of information related to other domains, posing significant risks to data security.
Affected Version(s)
Cisco Firepower Management Center 6.2.3.12
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.10