
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20301 is a missing authorization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software that allows an authenticated, low-privileged, remote attacker to access troubleshoot files belonging to a different domain. The vulnerability affects Cisco Secure FMC Software when configured for multitenancy using domains, spanning a wide range of versions from 6.2.3 through 7.6.0. It was discovered during internal Cisco security testing and publicly disclosed on August 14, 2025, as part of the August 2025 Cisco Secure Firewall bundled advisory. The CVSS v3.1 base score is 6.5 (Medium) (Cisco Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the FMC web interface fails to perform adequate authorization checks when a user requests a troubleshoot file, allowing direct access to files associated with domains other than the one the user is authorized for. An attacker exploits this by crafting a direct HTTP request to the URL of a troubleshoot file belonging to a different domain managed on the same FMC instance, bypassing tenant isolation controls. The attack requires only low-privilege authentication and no user interaction, and the scope remains unchanged (no privilege escalation beyond file read). No public proof-of-concept code has been identified (Cisco Advisory).
Successful exploitation allows a low-privileged attacker to retrieve troubleshoot files from domains they are not authorized to access on the same FMC instance, resulting in unauthorized disclosure of sensitive information. Troubleshoot files may contain system configuration details, network topology data, policy information, and other confidential operational data that could facilitate further attacks or lateral movement within the managed environment. The impact is limited to confidentiality — there is no integrity or availability impact — but the cross-domain nature of the exposure is particularly significant in multitenant deployments where domain isolation is a security boundary (Cisco Advisory).
Cisco has released fixed software to address CVE-2025-20301; there are no workarounds available. Administrators should use the Cisco Software Checker tool to identify the earliest fixed release for their deployment and upgrade accordingly. As interim risk reduction measures, organizations should restrict access to the FMC web management interface to trusted networks and IP ranges, enforce strict role-based access controls, and monitor FMC access logs for anomalous cross-domain file access attempts. The vulnerability only affects FMC instances configured for multitenancy using domains, so single-domain deployments are not impacted (Cisco Advisory).
The vulnerability was disclosed as part of Cisco's August 2025 semiannual Secure Firewall bundled advisory publication, which also addressed related CVE-2025-20302. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Cisco security products from this bundle. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-20301 has been identified beyond standard vulnerability tracking and aggregation (Cisco Advisory, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."