CVE-2025-20265 (CNNVD-202508-1704)
中文标题:
Cisco Secure Firewall Management Center 注入漏洞
英文标题:
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
漏洞描述
中文描述:
Cisco Secure Firewall Management Center是美国思科(Cisco)公司的一个强大的网络安全管理工具。 Cisco Secure Firewall Management Center存在注入漏洞,该漏洞源于RADIUS认证阶段输入处理不当,可能导致执行任意命令。
英文描述:
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerability is due to a lack of proper handling of user input during the authentication phase. An attacker could exploit this vulnerability by sending crafted input when entering credentials that will be authenticated at the configured RADIUS server. A successful exploit could allow the attacker to execute commands at a high privilege level. Note: For this vulnerability to be exploited, Cisco Secure FMC Software must be configured for RADIUS authentication for the web-based management interface, SSH management, or both.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Firepower Management Center | 7.0.7 | - | - |
cpe:2.3:a:cisco:cisco_firepower_management_center:7.0.7:*:*:*:*:*:*:*
|
| Cisco | Cisco Firepower Management Center | 7.7.0 | - | - |
cpe:2.3:a:cisco:cisco_firepower_management_center:7.7.0:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 7.0.7 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:7.0.7:*:*:*:*:*:*:*
|
| cisco | secure_firewall_management_center | 7.7.0 | - | - |
cpe:2.3:a:cisco:secure_firewall_management_center:7.7.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-20265 |
2025-11-11 15:23:05 | 2025-11-11 07:40:08 |
| NVD | nvd_CVE-2025-20265 |
2025-11-11 15:00:59 | 2025-11-11 07:47:59 |
| CNNVD | cnnvd_CNNVD-202508-1704 |
2025-11-11 15:12:53 | 2025-11-11 08:00:05 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 注入
- cnnvd_id: 未提取 -> CNNVD-202508-1704
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 4
- references_count: 1 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']