Skip to content

H3-2026-0010

Cisco Secure Firewall Management Center Session Fixation Vulnerability

Category VULNERABILITY
Base Score 8.9

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted system. The vulnerability is due to the presence of static user credentials for a low-privileged account.

Impact

Remote unauthenticated attackers can log in with static low-privileged credentials to access sensitive data on the FMC host. Cisco notes this access can be combined with other FMC vulnerabilities to escalate privileges, though the credential exposure alone does not grant code execution.

References