Cisco Secure Firewall Management Center Software sftunnel Authentication Bypass (cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3)

high Nessus Plugin ID 348178

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Secure Firewall Management Center (FMC) is affected by multiple vulnerabilities.

- A denial of service (DoS) vulnerability exists in the sftunnel functionality due to improper memory management. An unauthenticated, remote attacker can exploit this issue, via a specially crafted packet, to cause the device to stop responding. (CVE-2026-20295)

- An authentication bypass vulnerability exists in the sftunnel functionality due to improper TLS certificate management. An unauthenticated, adjacent attacker can exploit this, via a specially crafted sftunnel connection request, to impersonate the peer device and gain access with manager-level (root) privileges. (CVE-2026-20323)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCws43281, CSCwu16917.

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws43281

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu16917

http://www.nessus.org/u?1404ec77

Plugin Details

Severity: High

ID: 348178

File Name: cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3.nasl

Version: 1.1

Type: Local

Family: CISCO

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

Percentile: 95.9

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-20295

CVSS v3

Risk Factor: High

Base Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/a:cisco:firepower_management_center

Required KB Items: Host/Cisco/firepower_mc/version

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-20295, CVE-2026-20323

CWE: 295

CISCO-SA: cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3

IAVA: 2026-A-1027

CISCO-BUG-ID: CSCws43281, CSCwu16917