PT-2025-33337 · Cisco · Cisco Secure Fmc
Published
2024-10-10
·
Updated
2025-08-15
·
CVE-2025-20301
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Secure FMC Software (affected versions not specified)
Description:
A vulnerability exists in the web-based management interface of Cisco Secure FMC Software that could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a different domain. This issue is due to missing authorization checks, allowing an attacker to directly access troubleshoot files belonging to other domains managed within the same Cisco Secure FMC instance. Successful exploitation could lead to the retrieval of sensitive information contained within these files.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Secure Fmc