
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20302 is a missing authorization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, specifically affecting multi-tenant deployments configured with domains. An authenticated, low-privileged, remote attacker can retrieve generated report files belonging to a different domain managed on the same FMC instance. The vulnerability was disclosed on August 14, 2025, as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. Affected versions span Cisco Secure FMC Software from 6.2.3 through 7.6.0. It carries a CVSS v3.1 base score of 4.3 (Medium) (Cisco Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the FMC web interface does not perform adequate authorization checks when a user requests a generated report file, allowing access to report files associated with domains other than the user's own. An attacker exploits this by directly constructing or guessing the URL/path to a report file generated for a different domain on the same FMC instance. The vulnerability only applies when the FMC is configured for multitenancy using domains; single-domain deployments are not affected. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (Cisco Advisory).
Successful exploitation allows a low-privileged authenticated attacker to read previously generated activity reports from domains they are not authorized to access, resulting in a confidentiality breach of cross-domain reporting data. The impact is limited to information disclosure — there is no integrity or availability impact, and the scope remains unchanged. In multi-tenant environments, this could expose sensitive network activity, policy events, or security telemetry from other organizational domains managed on the same FMC instance (Cisco Advisory, Feedly).
Cisco has released fixed software versions addressing CVE-2025-20302; customers should consult the Cisco Software Checker tool to identify the earliest fixed release for their specific version. There are no workarounds available for this vulnerability — the only remediation is upgrading to a patched release. Organizations should also review and enforce the principle of least privilege for FMC user accounts, and monitor for unauthorized cross-domain report access as a compensating control until patching is complete (Cisco Advisory).
The Center for Internet Security (CIS) published an advisory noting multiple vulnerabilities in Cisco security products disclosed in August 2025, including this issue, recommending prompt patching (CIS Advisory). No notable independent researcher commentary or significant social media discussion specific to CVE-2025-20302 has been identified, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."