CVE-2025-20148
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document.
This vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitting malicious content to an affected device and using the device to generate a document that contains sensitive information.
Leer descripción completaMostrar menos
A successful exploit could allow the attacker to alter the standard layout of the device-generated documents, read arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (Read Only).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Puntuación base: 8.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution75 % - Impacto secundario
T1090Proxycommand and control80 % - Impacto secundario
T1552.001Credentials In Filescredential access78 %
Ataque remoto autenticado (AV:N, PR:L) contra servicio de red. Inyección HTML permite ejecución de código, lectura de archivos y SSRF explícitamente mencionados.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-20148",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-20148",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-08-14T18:41:04.289481Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "Cisco",
"product": "Cisco Firepower Management Center",
"versions": [
{
"status": "affected",
"version": "7.2.4"
},
{
"status": "affected",
"version": "7.0.6"
},
{
"status": "affected",
"version": "7.2.4.1"
},
{
"status": "affected",
"version": "7.2.5"
},
{
"status": "affected",
"version": "7.4.0"
},
{
"status": "affected",
"version": "7.0.6.1"
},
{
"status": "affected",
"version": "7.2.5.1"
},
{
"status": "affected",
"version": "7.4.1"
},
{
"status": "affected",
"version": "7.2.6"
},
{
"status": "affected",
"version": "7.4.1.1"
},
{
"status": "affected",
"version": "7.0.6.2"
},
{
"status": "affected",
"version": "7.2.7"
},
{
"status": "affected",
"version": "7.2.5.2"
},
{
"status": "affected",
"version": "7.2.8"
},
{
"status": "affected",
"version": "7.4.2"
},
{
"status": "affected",
"version": "7.2.8.1"
},
{
"status": "affected",
"version": "7.0.6.3"
},
{
"status": "affected",
"version": "7.4.2.1"
},
{
"status": "affected",
"version": "7.2.9"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-08-14T17:15:35.313",
"references": [
{
"url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-html-inj-MqjrZrny",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@cisco.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document.\r\n\r\nThis vulnerability is due to improper validation of user-supplied data. An attacker could exploit this vulnerability by submitting malicious content to an affected device and using the device to generate a document that contains sensitive information. A successful exploit could allow the attacker to alter the standard layout of the device-generated documents, read arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (Read Only)."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la interfaz de administración web del software Cisco Secure Firewall Management Center (FMC) podría permitir que un atacante remoto autenticado inyecte contenido HTML arbitrario en un documento generado por el dispositivo. Esta vulnerabilidad se debe a una validación incorrecta de los datos proporcionados por el usuario. Un atacante podría explotar esta vulnerabilidad enviando contenido malicioso a un dispositivo afectado y utilizándolo para generar un documento con información confidencial. Una explotación exitosa podría permitir al atacante alterar el diseño estándar de los documentos generados por el dispositivo, leer archivos arbitrarios del sistema operativo subyacente y realizar ataques de Server-Side Request Forgery (SSRF). Para explotar esta vulnerabilidad, el atacante debe tener credenciales válidas para una cuenta de usuario con al menos el rol de Analista de Seguridad (Solo Lectura)."
}
],
"lastModified": "2026-06-17T08:40:47.167",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E4D83B4-9697-4071-AC9F-7ADC86A6B529"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F81F708-ACED-4E42-8CA9-116B5C4F5141"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C86116B-8475-40A0-A507-D4A7947F5F2C"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.0.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B98BFDB6-0884-4A5B-B2F6-102AE22665C9"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36C229AB-2851-48D4-815A-63AAB4462A24"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DA4BCFC-8237-4F5C-9863-523EE7D8619B"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07693A92-7D84-45A1-ACD6-D83AE41D504B"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C78050A-A5FB-427B-BF0D-0353B240A4FF"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.5.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85E76AE7-12AC-4419-AE66-43730B173B4E"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D803EC9-26EE-4799-A435-C782C92739CF"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EEF87CD-2335-4886-A65C-4E33775AEC52"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "953EB81A-1B53-4A57-9F59-D4A7D37E657E"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CB534BC-3E4D-4484-AFD0-69524B1F07F9"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.2.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6514BF0-5A21-4C3A-9D9D-49677D7A2409"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6BD1665-7824-4D98-A930-432CBDA4EAD5"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8056E69-22FA-4935-A576-916805D90C62"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.4.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A80BBBE-DB5E-460A-8621-6E28D2BD6E44"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B33F953-FEF3-4C46-A12A-2A42D8339D6E"
},
{
"criteria": "cpe:2.3:a:cisco:secure_firewall_management_center:7.4.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2C8DF03-2280-48B8-AC1E-4AAA31A36BDC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}