Use of hard-coded credentials in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2020-3318

 

Use of hard-coded credentials in Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - CVE-2020-3318

Published: May 11, 2020


Vulnerability identifier: #VU27681
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3318
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to vulnerable system.

The vulnerability exists due to a system account that has a default and static password and that is not controlled by the system administrator. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC)

How to mitigate CVE-2020-3318

Install updates from vendor's website.

Cisco Secure Firewall Management Center (formerly Firepower Management Center, FMC) - update to 6.5.0

External References

Related Security Bulletins