Cisco Secure Firewall Manageme... Note

Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability

A critical vulnerability exists in Cisco Secure Firewall Management Center (FMC) Software's RADIUS subsystem. This flaw could permit an unauthenticated, remote attacker to inject and execute arbitrary shell commands on the device. The vulnerability stems from improper handling of user input during the authentication process. Attackers can exploit this by sending specially crafted credentials to the RADIUS server. A successful exploitation would grant the attacker high-privilege command execution. Crucially, this vulnerability can only be exploited if Cisco Secure FMC Software is configured for RADIUS authentication. This applies to either the web-based management interface, SSH management, or both. Cisco has released software updates to fix this issue. There are no available workarounds to mitigate this vulnerability. The advisory provides further details and can be found at the provided link.