Cisco Secure Firewall Management Center RADIUS Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the RADIUS subsystem of Cisco Secure Firewall Management Center (FMC) Software) releases 7.0.7 and 7.7.0, when RADIUS authentication is enabled. This vulnerability allows an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. The issue arises from improper handling of user input during the authentication process. Exploitation involves sending crafted input as credentials to be authenticated by a configured RADIUS server. Successful exploitation could enable the execution of commands with high privileges.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device with high privileges.

Remediation

Cisco has released free software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance. To determine exposure to this vulnerability, use the Cisco Software Checker tool.

Added: Aug 14, 2025, 5:48 PM
Updated: Aug 14, 2025, 5:48 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
7.0
remediation
7.9
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.