Authorization Bypass in Cisco Secure FMC Management Interface
CVE-2025-20302

4.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
14 August 2025

Badges

👾 Exploit Exists

What is CVE-2025-20302?

A security flaw in the web-based management interface of Cisco Secure FMC Software allows low-privileged authenticated attackers to retrieve reports generated for different domains managed within the same Cisco Secure FMC instance. The vulnerability arises from missing authorization checks, enabling an attacker to access sensitive activity reports that are not meant for their domain. This could lead to unauthorized disclosure of information related to other domains, posing significant risks to data security.

Affected Version(s)

Cisco Firepower Management Center 6.2.3.12

Cisco Firepower Management Center 6.2.3.1

Cisco Firepower Management Center 6.2.3.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20302 : Authorization Bypass in Cisco Secure FMC Management Interface