Who is affected
Cisco Secure Firewall Management Center (FMC), formerly known as Firepower Management Center, contains a hard-coded password vulnerability. An unauthenticated attacker on the network can log in with a low-privileged account to reach sensitive data. The record does not specify which versions of FMC are affected or whether only certain deployment modes (cloud, on-premises, or both) are in scope.
How to check whether this touches you
- Inventory your Cisco FMC deployments: note hostname, deployment model (on-premises or cloud-hosted), and current version from the system dashboard.
- Confirm network reachability by checking whether the FMC management interface (typically port 443) is accessible from untrusted networks, including the internet.
- Retrieve the exact version number from the FMC console or API; version banners alone are not definitive because backported patches may exist outside standard release cycles.
- If you operate a cloud-hosted FMC instance, verify the underlying service version through Cisco's cloud portal or support dashboard.
- Check your configuration management database or asset discovery logs to identify all FMC instances you may have forgotten about.
What to do
- Obtain the specific list of affected versions and patches from Cisco's security advisory (linked in the CISA entry); do not rely on version number alone to determine status.
- If you cannot patch immediately, restrict network access to the FMC management interface to known administrative subnets using firewall rules or security group policies.
- Review and strengthen authentication controls on any accounts with access to FMC, even low-privileged ones, and audit recent login activity for those accounts.
- Enable logging of all authentication attempts and configuration changes on FMC; ship these logs to a centralised security information and event management (SIEM) system or syslog collector outside FMC itself.
- Plan patching according to CISA BOD 26-04 timelines; if the patch is unavailable or mitigations do not adequately reduce your risk, escalate to your change advisory board and security leadership for a decision on continued use.
If you find you were exposed
Exploitation of hard-coded credentials typically precedes detection and public disclosure by months or years. Examine FMC audit logs and authentication records as far back as your retention allows—at minimum the past 90 days—for successful logins from unexpected source addresses or at unusual times. Check for changes to firewall rules, user accounts, and policy objects that you do not recognise. If log retention on FMC is limited, query upstream syslog or SIEM records if they exist, and consider engaging Cisco support or a forensic specialist to help reconstruct the timeline of access.