zero-day Cisco Talos Intelligence

Cisco Secure Firewall -hallintajärjestelmän aktiivinen nollapäivähyökkäys sallii täyden etähallinnan

Cisco Talos varoittaa kriittisen CVSS 10.0 -haavoittuvuuden aktiivisesta hyväksikäytöstä Cisco Secure Firewall Management Center -alustoilla, mikä mahdollistaa etäkäyttäjän täyden root-hallinnan ilman todennusta.

Cisco Secure Firewall -hallintajärjestelmän aktiivinen nollapäivähyökkäys sallii täyden etähallinnan

Cybersecurity leader Cisco Systems and threat intelligence arm Cisco Talos confirmed active in-the-wild exploitation of a maximum-severity zero-day vulnerability rated CVSS 10.0 affecting Cisco Secure Firewall Management Center (FMC). The platform serves as the central control plane for enterprise network access, firewall clustering, and VPN termination across thousands of enterprise and government perimeters.

According to Cisco's technical bulletin, the vulnerability stems from an improper authentication validation routine within the appliance web framework and REST API daemon on TCP port 443. By submitting specially crafted HTTP requests across network perimeters, unauthenticated remote attackers can bypass identity verification controls entirely (Authentication Bypass). Once bypassed, the attacker can leverage command execution hooks to run arbitrary operating system commands with full administrative root privileges.

Forensic investigations conducted by Cisco Talos demonstrate that active adversaries in the wild leverage this unauthorized access to establish covert persistence within the underlying Linux kernel. Attackers have been observed creating hidden binaries under `/usr/local/sf/bin/`, tampering with Snort inspection rules, and modifying syslog audit trails to conceal lateral traversal deeper into victim enterprise enclaves (incident-response).

Compromising the firewall management plane yields total control over corporate network boundaries. Threat actors can silently alter traffic inspection rules, disable intrusion prevention systems, exfiltrate stored SSL certificates, and extract active session secrets. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog with immediate federal patching mandates.

Käytännön toimenpiteet tietoturvatiimeille

  • Deploy Official Cisco Patches Immediately: Apply the latest firmware updates and security hotfixes released on Cisco's advisory portal without delay.
  • Enforce Strict Management Plane Isolation: Ensure that FMC management interfaces (HTTPS port 443) are completely inaccessible from the public internet, restricting access strictly to dedicated out-of-band management subnets.
  • Audit Web Server and Syslog Telemetry: Inspect HTTP daemon access logs (`/var/log/httpd/access_log`) for abnormal POST requests and unauthenticated URI traversals.
  • Validate Administrator Accounts and API Keys: Audit local user databases and API authorization tokens created over the preceding 14-day operational window.
  • Monitor Outbound Egress From Management Nodes: Scrutinize all outbound traffic originating from FMC network interfaces to identify anomalous connections to unauthorized external C2 infrastructure.

Todisteiden tila

  • Confirmed: Cisco Talos officially validated active in-the-wild exploitation of the CVSS 10.0 vulnerability against internet-facing appliances.
  • Reported: CISA has added the flaw to the federal Known Exploited Vulnerabilities catalog with binding remediation directives.
  • Unconfirmed: Formal attribution to a specific state-sponsored APT cluster remains under investigative review.

Lyhyesti

  • Critical CVSS 10.0 zero-day in Cisco FMC permits unauthenticated remote attackers to execute arbitrary commands with full root privileges.
  • Adversaries tamper with firewall policies, disable alert telemetry, and establish persistent footholds on perimeter controllers.
  • Security teams must patch appliances immediately and isolate management ports from external network exposure.

Lähteet ja viitteet

← Kaikki uutiset Työkalut