PT-2025-33337 · Cisco · Cisco Secure Fmc

Published

2024-10-10

·

Updated

2025-08-15

·

CVE-2025-20301

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Secure FMC Software (affected versions not specified)
Description: A vulnerability exists in the web-based management interface of Cisco Secure FMC Software that could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain. This issue is due to missing authorization checks, allowing an attacker to directly access troubleshoot files belonging to other domains managed within the same Cisco Secure FMC instance. Successful exploitation could lead to the retrieval of sensitive information contained within these files.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-11006
CVE-2025-20301

Affected Products

Cisco Secure Fmc