Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Cisco Secure FMC Software's Apache JServ Protocol (AJP) connector could allow an unauthenticated attacker to impersonate a peer device. This is due to incorrect initialization of encryption parameters at boot time, potentially allowing an attacker to execute commands as root and gain full control over FMC REST APIs if a secure tunnel connection is down.
- Unauthenticated impersonation via AJP connector.
- Affects Cisco Secure FMC Software's management APIs.
- Confirm relevance and exposure for management systems.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could impersonate a peer device by sending specially crafted packets to the Apache JServ Protocol (AJP) connector, provided the secure tunnel between Cisco Secure FMC and FTD software is not active. This vulnerability arises from incorrect initialization of encryption parameters during the connector's startup. A successful exploit allows the attacker to execute commands as root, gaining complete control over the FMC REST APIs.
- No authentication required to initiate attack.
- Exploited by sending crafted packets to AJP connector.
- Results in root command execution and API control.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated, remote attacker could impersonate a peer device, potentially executing commands as root and gaining full control over FMC REST APIs when the AJP connector's encryption parameters are not initialized correctly at boot time and the secure tunnel between Cisco Secure FMC and FTD software is down.
- System data and device control.
- Sending crafted packets to the AJP connector.
- Full control of FMC REST APIs.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in Cisco Secure FMC Software's AJP connector requires immediate attention from teams managing Cisco security infrastructure. The first step is to identify all instances of affected Cisco FMC software, assess their exposure, and determine business criticality. Subsequently, coordinate with the relevant platform or security operations teams to plan and execute remediation, considering any dependencies and potential operational impacts.
- Own by infrastructure and platform teams.
- Verify AJP connector exposure and reachability.
- Plan for remediation based on risk.