Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/08/cisco-warns-of-cvss-100-fmc-radius-flaw.html
ONE SENTENCE SUMMARY:
Cisco released security updates to fix critical vulnerabilities in Secure Firewall Management Center Software, including a severe RADIUS subsystem flaw.
MAIN POINTS:
- Cisco released updates for a critical flaw in Secure Firewall Management Center Software.
- The flaw, CVE-2025-20265, has a CVSS score of 10.0.
- An attacker could inject arbitrary shell commands via the RADIUS subsystem.
- Proper user input handling was lacking, leading to potential high-privilege command execution.
- The vulnerability affects Cisco Secure FMC Software releases 7.0.7 and 7.7.0 with RADIUS enabled.
- No workarounds exist except applying Cisco’s provided patches.
- Other high-severity vulnerabilities (CVSS 8.6 – 7.7) have also been resolved.
- These involve various denial-of-service vulnerabilities across several Cisco software components.
- No active exploitation of these flaws has been reported so far.
- Users are advised to update to the latest software version promptly.
TAKEAWAYS:
- Immediate patching is crucial to prevent potential exploits of the critical RADIUS vulnerability.
- Cisco has addressed multiple high-severity vulnerabilities alongside the critical one.
- Lack of active exploitations doesn’t negate the urgency of applying updates.
- Regular security updates are vital for maintaining network security integrity.
- Monitoring and quick response to security advisories can significantly reduce risk exposure.