Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

Cisco Issues Urgent Alert! Critical Zero-day Vulnerability on Firewall Management Center (FMC) Under Attack

Cisco has issued a high-severity security advisory for CVE-2024-20353 on its Secure Firewall Management Center (FMC), caused by embedded static credentials. This vulnerability is actively being exploited in zero-day attacks, and system administrators are urged to update patches immediately.

Edited by SyncTech Solution Published Source Original source
Cisco Issues Urgent Alert! Critical Zero-day Vulnerability on Firewall Management Center (FMC) Under Attack

πŸ“Œ Key Takeaways:
- A high-severity security vulnerability (CVE-2024-20353) has been found in Cisco Secure Firewall Management Center (FMC), stemming from static credentials embedded in the system.
- Hackers are actively exploiting this vulnerability in zero-day attacks to gain remote access to devices without authentication.
- Cisco has released a patch to fix this; administrators should update as soon as possible to prevent attacks.

Cisco has issued an important security alert regarding a critical vulnerability in its Secure Firewall Management Center (FMC) software, the central tool for managing Cisco Firewall devices. The vulnerability, identified as CVE-2024-20353, is rated as high severity.

The root cause of this vulnerability is 'Static Credential,' meaning login information (such as Username/Password) is directly embedded or hardcoded into the software. This allows unauthorized attackers to use these credentials to gain remote access to connected devices, posing a significant risk to network infrastructure.

πŸ’₯ Most concerning is Cisco's confirmation that this vulnerability is already being exploited in zero-day attacks. This means hackers discovered and leveraged the flaw before the manufacturer released a corrective patch, leaving many organizations unknowingly at risk. Such access could lead to the theft of sensitive data, alteration of Firewall settings to facilitate further attacks, or even complete network compromise.

πŸ›‘οΈ For remediation, Cisco has already released software updates to close the vulnerability. There are no other workarounds besides updating the patch. Therefore, all administrators using Cisco FMC should promptly check their software version and proceed with updating to the latest version as quickly as possible to eliminate this risk and prevent potential damage to their organizations.

πŸ’¬ Does your organization use Cisco Firewall? Have you checked and updated the latest security patches yet?

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.