Cisco Secure Firewall Manageme... Note

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software Command Injection Vulnerability

A vulnerability exists in the command-line interface of Cisco Secure Firewall Management Center and Threat Defense software. This flaw allows an authenticated, local attacker to execute arbitrary commands. The issue stems from improper input validation within specific CLI commands. An attacker can exploit this by injecting operating system commands into a legitimate command. Successful exploitation enables the attacker to bypass the restricted command prompt. To exploit this vulnerability, the attacker requires valid Administrator credentials. Cisco has released software updates to fix this vulnerability. There are no workarounds available to mitigate this issue. The security impact rating for this vulnerability is Medium. The assigned CVE identifier is CVE-2025-20220.