A serious flaw in a widely used firewall management platform is being actively exploited by attackers right now, and government cyber authorities have set a tight deadline for fixing it.
- What it is: A vulnerability in Cisco Secure Firewall Management Center (FMC), the software many businesses use to control their firewalls, lets an attacker log in with a low-level account using a hidden, built-in password that should never have been accessible.
- Who is affected: Any business running an on-site Cisco Secure Firewall Management Center appliance that is reachable from the internet, particularly on older software versions.
- What the risk is: Once inside, an attacker can see firewall rules, VPN settings, device inventories and security logs, information that can be used to plan a bigger attack or disable your defences entirely.
- What action is needed: The US Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities catalogue in late July, alongside a separate, actively exploited flaw in Check Point's SmartConsole management software. Both vendors have released fixes and are urging customers to patch immediately.
If your business manages its own firewall infrastructure rather than relying on a managed service, we recommend confirming with your IT provider that all management platforms, not just the firewalls themselves, are on the latest patched version.
Sources: CISA advisory, Check Point advisory