Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A security vulnerability in Cisco's firewall management software allows unauthorized users to log in using a hidden, low-privileged account to view sensitive information.
English Brief
A security vulnerability in Cisco's firewall management software allows unauthorized users to log in using a hidden, low-privileged account to view sensitive information.
الموجز العربي
ثغرة في برنامج Cisco Secure Firewall Management Center تتعلق ببيانات اعتماد ثابتة
ثغرة أمنية في برنامج إدارة جدار الحماية من شركة سيسكو تسمح لمستخدمين غير مصرح لهم بتسجيل الدخول باستخدام حساب منخفض الصلاحيات للاطلاع على معلومات حساسة.
- 1Identify current FMC software version; # 2. Navigate to the Cisco Software Central portal; # 3. Download the latest security patch for FMC as advised in the security advisory; # 4. Perform a system backup before applying patches; # 5. Apply the update to the FMC appliance; # 6. Restrict access to the management interface to trusted IP addresses via ACLs.
English Advisory
// Intelligence Summary
A static credential vulnerability exists in the web interface of Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote attackers to authenticate as a low-privileged user.
التقرير العربي
// ملخص استخباراتي
توجد ثغرة أمنية تتعلق ببيانات اعتماد ثابتة في واجهة الويب الخاصة ببرنامج Cisco Secure Firewall Management Center (FMC)، مما يسمح للمهاجمين غير المصرح لهم بالدخول عن بُعد باستخدام حساب منخفض الصلاحيات.
// Technical Context
The vulnerability stems from hard-coded or static credentials assigned to an internal, low-privileged account within the FMC software. Attackers can leverage these credentials to establish a session, accessing system data that would otherwise be protected from unauthenticated entities.
// السياق الفني
تنتج هذه الثغرة عن وجود بيانات اعتماد ثابتة أو مبرمجة مسبقاً لحساب داخلي منخفض الصلاحيات داخل برنامج FMC. يمكن للمهاجمين استغلال هذه البيانات لإنشاء جلسة دخول والوصول إلى بيانات النظام التي يجب أن تكون محمية من الدخول غير المصرح به.
// Exposure Notes
The attack surface is limited to systems where the management interface is exposed to the internet. While described as a 'low-privileged' account access, Cisco notes that this flaw can be chained with other vulnerabilities to facilitate privilege escalation.
// ملاحظات التعرض
ينحصر نطاق الخطر في الأنظمة التي تكون فيها واجهة الإدارة مكشوفة للإنترنت. على الرغم من تصنيف الحساب كـ 'منخفض الصلاحيات'، أشارت سيسكو إلى إمكانية ربط هذه الثغرة مع ثغرات أخرى لتسهيل رفع مستوى الصلاحيات.
// Defensive Priority
Cisco has released software updates to address this issue. There are no available workarounds; patching is the only effective defense. For more details, see: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
// أولوية الدفاع
أصدرت سيسكو تحديثات برمجية لمعالجة هذه الثغرة. لا توجد حلول بديلة؛ لذا فإن تطبيق التحديثات هو الوسيلة الوحيدة للحماية. لمزيد من التفاصيل، راجع: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Mitigation Checklist
- 1Identify current FMC software version; # 2. Navigate to the Cisco Software Central portal; # 3. Download the latest security patch for FMC as advised in the security advisory; # 4. Perform a system backup before applying patches; # 5. Apply the update to the FMC appliance; # 6. Restrict access to the management interface to trusted IP addresses via ACLs.
قائمة إجراءات التخفيف
- 1تحديد إصدار برنامج FMC الحالي؛ # 2. الانتقال إلى بوابة Cisco Software Central؛ # 3. تنزيل أحدث تصحيح أمني لـ FMC كما هو موصى به في الإشعار الأمني؛ # 4. إجراء نسخ احتياطي للنظام قبل تطبيق التصحيحات؛ # 5. تطبيق التحديث على جهاز FMC؛ # 6. تقييد الوصول إلى واجهة الإدارة وحصرها في عناوين IP موثوقة عبر قوائم التحكم في الوصول (ACLs).
- Source: Cisco Security Advisories
# 1. Identify current FMC software version; # 2. Navigate to the Cisco Software Central portal; # 3. Download the latest security patch for FMC as advised in the security advisory; # 4. Perform a system backup before applying patches; # 5. Apply the update to the FMC appliance; # 6. Restrict access to the management interface to trusted IP addresses via ACLs.