Cisco's exploited FMC bypass gives an unauthenticated caller root command execution.
HTTP reachability to the management interface is enough to reach the vulnerable path.
Cisco Secure Firewall Management Center, the on-premises management appliance for Cisco firewalls, and the affected Cisco Security Cloud Control firewall-management service.
Unauthenticated command execution as root on firewall-management infrastructure
Although ranked below the Bluetooth disclosure, it leads because exploitation is active, reaches root on the firewall-management plane, and has already produced several post-compromise toolsets; the Bluetooth elevation paths remain unreproduced.
Detail and 4 sources
A boot-created system process exposes an alternate route from crafted unauthenticated web requests to root-capable script execution.
Cisco observed web shells, Cyclops Blink, credential harvesting, tunnels, and ransomware staging across three intrusion clusters.
Cisco has published fixes, and CISA added the flaw to its exploited-vulnerability catalog on September 9.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
The public materials do not expose the hotfix diff or package contents, so the image-acceptance and revocation questions could not be resolved beyond unknown.