Authorization Bypass in Cisco Secure FMC Management Interface
CVE-2025-20302
What is CVE-2025-20302?
A security flaw in the web-based management interface of Cisco Secure FMC Software allows low-privileged authenticated attackers to retrieve reports generated for different domains managed within the same Cisco Secure FMC instance. The vulnerability arises from missing authorization checks, enabling an attacker to access sensitive activity reports that are not meant for their domain. This could lead to unauthorized disclosure of information related to other domains, posing significant risks to data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Firepower Management Center 6.2.3.12
Cisco Firepower Management Center 6.2.3.1
Cisco Firepower Management Center 6.2.3.10
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved