CVE-2025-20302
Cisco Secure Firewall Management Center vulnerability analysis and mitigation

Overview

CVE-2025-20302 is a missing authorization vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, specifically affecting multi-tenant deployments configured with domains. An authenticated, low-privileged, remote attacker can retrieve generated report files belonging to a different domain managed on the same FMC instance. The vulnerability was disclosed on August 14, 2025, as part of Cisco's August 2025 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. Affected versions span Cisco Secure FMC Software from 6.2.3 through 7.6.0. It carries a CVSS v3.1 base score of 4.3 (Medium) (Cisco Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the FMC web interface does not perform adequate authorization checks when a user requests a generated report file, allowing access to report files associated with domains other than the user's own. An attacker exploits this by directly constructing or guessing the URL/path to a report file generated for a different domain on the same FMC instance. The vulnerability only applies when the FMC is configured for multitenancy using domains; single-domain deployments are not affected. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (Cisco Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to read previously generated activity reports from domains they are not authorized to access, resulting in a confidentiality breach of cross-domain reporting data. The impact is limited to information disclosure — there is no integrity or availability impact, and the scope remains unchanged. In multi-tenant environments, this could expose sensitive network activity, policy events, or security telemetry from other organizational domains managed on the same FMC instance (Cisco Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a Cisco Secure FMC instance configured for multitenancy with multiple domains. Confirm the target version falls within the affected range (6.2.3 through 7.6.0).
  2. Authentication: Log in to the FMC web-based management interface using any valid low-privileged account (e.g., a user account with access to only one domain).
  3. Enumerate report file paths: Identify the URL structure used by the FMC to serve generated report files. Report files for different domains are stored or referenced with predictable or discoverable paths/identifiers.
  4. Access cross-domain report: Directly request the URL or file path of a report generated for a different domain (e.g., by modifying domain identifiers or report IDs in the request), bypassing the missing authorization check.
  5. Exfiltrate report data: Read the retrieved report, which may contain network activity logs, security events, or policy information from the target domain (Cisco Advisory).

Indicators of compromise

  • Logs: FMC web server access logs showing authenticated requests from a user account to report file URLs associated with domains other than their own; repeated access attempts to report endpoints with varying domain or report identifiers.
  • Network: Unusual HTTP GET requests to FMC report download endpoints from user accounts that do not belong to the domain associated with the requested report.
  • Behavioral: A low-privileged user account accessing or downloading reports at a frequency or volume inconsistent with their assigned domain responsibilities.

Mitigation and workarounds

Cisco has released fixed software versions addressing CVE-2025-20302; customers should consult the Cisco Software Checker tool to identify the earliest fixed release for their specific version. There are no workarounds available for this vulnerability — the only remediation is upgrading to a patched release. Organizations should also review and enforce the principle of least privilege for FMC user accounts, and monitor for unauthorized cross-domain report access as a compensating control until patching is complete (Cisco Advisory).

Community reactions

The Center for Internet Security (CIS) published an advisory noting multiple vulnerabilities in Cisco security products disclosed in August 2025, including this issue, recommending prompt patching (CIS Advisory). No notable independent researcher commentary or significant social media discussion specific to CVE-2025-20302 has been identified, consistent with its medium severity rating and lack of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Cisco Secure Firewall Management Center vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20131CRITICAL10
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
YesYesMar 04, 2026
CVE-2025-20265CRITICAL10
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20301MEDIUM6.5
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20306MEDIUM4.9
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025
CVE-2025-20302MEDIUM4.3
  • Cisco Secure Firewall Management Center logoCisco Secure Firewall Management Center
  • cpe:2.3:a:cisco:secure_firewall_management_center
NoYesAug 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management