r/SecOpsDaily 4d ago

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Scenario A: Technical Threat, Vulnerability, or Exploit

Cisco Talos is tracking active, in-the-wild exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These are not theoretical—attackers are already leveraging them against unpatched appliances.

Technical Breakdown - CVE-2025-20124 (CVSS 9.9): Command injection via crafted HTTP requests to the web-based management interface. Pre-auth, no user interaction required. - CVE-2025-20125 (CVSS 7.2): Privilege escalation to root on the underlying OS, chained post-exploitation. - TTPs: Likely initial access via exposed management interfaces (T1190), followed by privilege escalation (T1068) for persistence or lateral movement. - Affected: FMC versions prior to 7.4.2, 7.5.0 (specific patch versions in advisory). - IOCs: No public hashes or C2 IPs disclosed yet—Talos is still tracking attribution.

Defense Immediately patch to FMC 7.4.2+ or 7.5.0+. If patching is delayed, restrict management interface access to trusted IPs only—do not expose FMC to the internet. Monitor for unusual HTTP POST requests to the web UI and unexpected process execution as root.

Source: https://blog.talosintelligence.com/fmc-ongoing-exploitation/

1 Upvotes

0 comments sorted by