CVE-2026-20323
Last modified
CVE-2026-20323 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate.
Description
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate. A successful exploit could allow the attacker to become a registered sftunnel peer with root access. Note: The attack is successful only if the sftunnel connection is down or the attack can disrupt the sftunnel connection long enough to execute the attack.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Secure Firewall Management Center (FMC) | 7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.3.1; 7.2.3; 7.2.3.1; 7.2.4; 7.0.6; 7.2.4.1; 7.2.5; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.4.1.1; 7.0.6.2; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.2.10.1; 7.0.8.1; 7.6.2.1; 7.2.10.2; 7.7.10.1; 7.4.2.4; 7.4.3; 7.6.3; 7.7.11; 7.6.4; 10.0.0; 7.4.4; 7.4.5; 7.0.9; 7.2.11; 7.7.12; 7.6.5; 7.4.6; 10.0.1; 7.4.7; 7.0.10 |
| Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | 7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.2.3; 7.3.1; 7.2.4; 7.0.6; 7.2.5; 7.2.4.1; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.0.6.2; 7.4.1.1; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.7.11; 7.0.8.1; 7.6.2.1; 7.7.10.1; 7.4.2.4; 7.2.10.2; 7.4.3; 7.6.4; 10.0.0; 7.4.4; 7.0.9; 7.2.11; 7.4.7; 7.0.10 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-20323?
How severe is CVE-2026-20323?
How do I fix CVE-2026-20323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-20317As part of Cisco's ongoing commitment to proactive security …10
- CVE-2026-20318As part of Cisco's ongoing commitment to proactive security …9.6
- CVE-2026-20319As part of Cisco's ongoing commitment to proactive security …7.5
- CVE-2026-2032Malicious scripts that interrupt new tab page loading could …4.3
- CVE-2026-20320A vulnerability in the Open Client Interface (OCI) XML Parse…7.5
- CVE-2026-20322As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-20324A vulnerability in the sftunnel inter-device communication p…9.9
- CVE-2026-20325As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-20326As part of Cisco's ongoing commitment to proactive security …9.8
- CVE-2026-20327A vulnerability in the web-based management interface of Cis…6.5
- CVE-2026-20329As part of Cisco's ongoing commitment to proactive security …9.9
- CVE-2026-2033MLflow Tracking Server Artifact Handler Directory Traversal …8.1
Are you affected by CVE-2026-20323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
