Interestana
Home/News/Cisco FMC Vulnerabilities Exploited by Ransomware and State Hackers
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Cisco FMC Vulnerabilities Exploited by Ransomware and State Hackers

Cisco Talos, the threat intelligence arm of Cisco Systems, has reported that two recently patched vulnerabilities within Cisco Secure Firewall Management Center (FMC) are currently being exploited by multiple threat actors. These exploits are linked to both ransomware operations and state-sponsored cyberattacks, indicating a significant security risk for organizations utilizing the affected Cisco product. The vulnerabilities, identified as CVE-2023-20197 and CVE-2023-20200, were patched by Cisco in November 2023. However, the ongoing exploitation highlights that a substantial number of organizations have not yet applied these critical security updates.

Cisco Talos has identified at least three distinct threat clusters actively leveraging these flaws. One cluster is associated with ransomware attacks, aiming to encrypt victim data and demand payment for its decryption. Another cluster is linked to state-sponsored espionage or disruptive cyber activities, suggesting that nation-state actors are also capitalizing on these weaknesses for their strategic objectives. The third cluster's specific objectives are still under investigation but are also considered malicious. The exploitation of CVE-2023-20197, a critical authentication bypass vulnerability, allows unauthenticated attackers to gain administrative access to the FMC. CVE-2020-20200, rated as high severity, enables attackers to execute arbitrary commands on the underlying operating system of the FMC. The combination of these vulnerabilities can lead to complete compromise of the firewall management system.

Cisco Secure Firewall Management Center is a centralized platform used to manage and monitor Cisco's range of firewall devices. It provides administrators with tools for policy configuration, threat detection, and reporting across an organization's network security infrastructure. Compromising the FMC can grant attackers extensive control over an organization's network perimeter defenses, allowing them to disable security measures, redirect traffic, deploy malware, or exfiltrate sensitive data. The fact that these vulnerabilities are being actively exploited by sophisticated threat actors, including state-sponsored groups, underscores the urgency for organizations to patch their FMC deployments. Cisco has urged all users to upgrade their FMC software to the latest versions that address these vulnerabilities to mitigate the risk of compromise. The ongoing exploitation serves as a stark reminder of the persistent threat landscape and the importance of timely patch management for network security devices.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next