Cisco announced the highest level of security in Firewall Management Center: Risk of Remote Code Operation
The Cisco announced the critical security deficit (CV-2025-20265) discovered in the Radius component in the SECURE Firewall Management Center software and evaluated with CVSS 10.0 (CV-2025-20265).
Technical dimension of the deficit
CV-2025-20265 is due to the fact that the user input is not correctly processed during the Radius authentication process.
Which versions are affected
According to Cisco, the Open is open, in the 7.0.7 and 7.7.0 versions of FMC software, Radius authentication occurs when the authentication is active.
Updates Published
Cisco has released free software updates to relieve the vulnerability.
Temporary solution option
The only temporary solution proposed in the environments that cannot be loaded with patch, the use of local user accounts, LDAP or SAML -based authentication methods instead of disabled Radius authentication.
Has not been abused yet
Open, Cisco security researcher Brandon Sakai was discovered in internal tests.
Additional security patches
Cisco has also closed 13 high -importance security vulnerabilities, such as Snort 3, ASA, FTD, IOS and IOS XE, such as service rejection (DOS) and HTML injection.
Kaynak: CUMHA - CUMHUR HABER AJANSI
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0


