CVE-2025-20301
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2025-20301 is a missing authorization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, low-privileged, remote attacker to access troubleshoot files belonging to a different domain. The vulnerability affects Cisco Secure FMC Software when configured for multitenancy using domains, spanning a wide range of versions from 6.2.3 through 7.6.0. It was discovered during internal Cisco security testing and publicly disclosed on August 14, 2025, as part of the August 2025 Cisco Secure Firewall bundled advisory. The CVSS v3.1 base score is 6.5 (Medium) (Cisco Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the FMC web interface fails to perform adequate authorization checks when a user requests a troubleshoot file, allowing direct access to files associated with domains other than the one the user is authorized for. An attacker exploits this by crafting a direct HTTP request to the URL of a troubleshoot file belonging to a different domain managed on the same FMC instance, bypassing tenant isolation controls. The attack requires only low-privilege authentication and no user interaction, and the scope remains unchanged (no privilege escalation beyond file read). No public proof-of-concept code has been identified (Cisco Advisory).

Impact

Successful exploitation allows a low-privileged attacker to retrieve troubleshoot files from domains they are not authorized to access on the same FMC instance, resulting in unauthorized disclosure of sensitive information. Troubleshoot files may contain system configuration details, network topology data, policy information, and other confidential operational data that could facilitate further attacks or lateral movement within the managed environment. The impact is limited to confidentiality — there is no integrity or availability impact — but the cross-domain nature of the exposure is particularly significant in multitenant deployments where domain isolation is a security boundary (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Cisco Secure FMC instance configured for multitenancy with multiple domains. Confirm the target version falls within the affected range (6.2.3 through 7.6.0).
  2. Authentication: Log in to the FMC web-based management interface using any valid low-privileged account (e.g., a user with access to only one domain).
  3. Enumerate troubleshoot file paths: Identify or guess the URL path structure used by the FMC to serve troubleshoot files for other domains. This may involve observing the URL pattern when generating a troubleshoot file for the attacker's own domain.
  4. Direct file access: Craft an HTTP GET request directly targeting the troubleshoot file URL of a different domain (e.g., substituting a different domain identifier in the URL), bypassing the missing authorization check.
  5. Retrieve sensitive data: Download the troubleshoot file for the unauthorized domain and extract sensitive information such as system configuration, network policies, or operational data (Cisco Advisory).

Indicators of compromise

  • Logs: FMC web server access logs showing authenticated requests from a user account to troubleshoot file URLs associated with domains other than those assigned to that user; repeated or sequential access to troubleshoot file endpoints across multiple domain identifiers.
  • Network: Unusual HTTP GET requests to FMC management interface URLs containing troubleshoot file paths with domain identifiers not matching the authenticated user's assigned domain.
  • Behavioral: A single low-privileged user account accessing troubleshoot files for multiple domains in a short time window; access to troubleshoot files outside of normal administrative hours or from unexpected source IP addresses.

Mitigation and workarounds

Cisco has released fixed software to address CVE-2025-20301; there are no workarounds available. Administrators should use the Cisco Software Checker tool to identify the earliest fixed release for their deployment and upgrade accordingly. As interim risk reduction measures, organizations should restrict access to the FMC web management interface to trusted networks and IP ranges, enforce strict role-based access controls, and monitor FMC access logs for anomalous cross-domain file access attempts. The vulnerability only affects FMC instances configured for multitenancy using domains, so single-domain deployments are not impacted (Cisco Advisory).

Community reactions

The vulnerability was disclosed as part of Cisco's August 2025 semiannual Secure Firewall bundled advisory publication, which also addressed related CVE-2025-20302. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco security products from this bundle. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-20301 has been identified beyond standard vulnerability tracking and aggregation (Cisco Advisory, CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20131CRITICAL10
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
YesYesMar 04, 2026
CVE-2025-20265CRITICAL10
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20301MEDIUM6.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20306MEDIUM4.9
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20302MEDIUM4.3
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management