A vulnerability in Cisco's Secure Firewall Management Center (FMC) is being actively exploited by attackers to access sensitive data on affected systems.
- What it is: hardcoded login credentials built into the Cisco FMC web interface let a remote attacker log in without needing valid credentials of their own.
- Who is affected: any business running Cisco Secure Firewall Management Center to administer their firewalls.
- What the risk is: attackers have used this flaw to access sensitive configuration data, and it can potentially be chained with other flaws for deeper access.
- What to do: apply Cisco's hotfix immediately. There is no workaround, and the flaw is already listed on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue.
If your business or IT provider manages firewalls through Cisco FMC, we recommend confirming the hotfix has been applied without delay.
Source: The Hacker News