Why the Cisco FMC Attack Surface Is Hard to See From Outside

Why the Cisco FMC Attack Surface Is Hard to See From Outside

为什么思科 FMC 的攻击面在外部难以察觉

CVE-2026-20079 in Cisco Secure Firewall Management Center is a pre-authentication bypass rated CVSS 10.0. An unauthenticated attacker sends a crafted HTTP request and executes scripts as root. Cisco Talos confirmed exploitation on 9 September 2026 across three separate intrusion clusters. The measurement problem is that the management console is not easy to find with the same techniques used for other edge devices. 思科安全防火墙管理中心(FMC)中的 CVE-2026-20079 是一个 CVSS 评分为 10.0 的预认证绕过漏洞。未经身份验证的攻击者可以发送精心构造的 HTTP 请求,并以 root 权限执行脚本。思科 Talos 在 2026 年 9 月 9 日确认了三个独立的入侵集群利用了该漏洞。测量该攻击面的难点在于,管理控制台无法通过用于其他边缘设备的常规技术轻松发现。

What the searches returned

搜索结果分析

ZoomEye queries for the FMC product fingerprint returned the following at the time of collection: 在收集数据时,针对 FMC 产品指纹的 ZoomEye 查询结果如下:

QueryCount
app=“Cisco Secure Firewall Management Center”0
vul.cve=“CVE-2026-20079”0
app=“Cisco Firepower”2
app=“Cisco ASA”114

A zero result is a real result here, not a failed query. It means no assets in the index matched that exact product fingerprint string. The same applies to the vul.cve query: ZoomEye had no assets indexed against that CVE identifier at collection time. Neither outcome means the product is not deployed or the vulnerability does not exist. It means the fingerprint and CVE-index approaches do not surface this population. 这里的零结果是真实的结果,而非查询失败。这意味着索引中没有任何资产匹配该精确的产品指纹字符串。同样的情况也适用于 vul.cve 查询:在收集数据时,ZoomEye 没有针对该 CVE 标识符索引到任何资产。但这两种结果并不意味着产品未部署或漏洞不存在,而是说明指纹识别和 CVE 索引方法无法覆盖这一群体。

Why management consoles resist fingerprinting

为什么管理控制台难以被指纹识别

The FMC web interface is an administrative console. It is typically placed behind a VPN, a jump host, or an internal network segment rather than exposed directly to the internet. When it is not internet-facing, it does not appear in an external asset index at all, regardless of how the query is written. The product fingerprint also depends on a signature that ZoomEye can recognize from a banner or response. A management interface that requires authentication before returning meaningful content, or that presents a generic login page, is harder to fingerprint than a service that advertises its product in a banner. FMC Web 界面是一个管理控制台。它通常部署在 VPN、跳板机或内部网段之后,而不是直接暴露在互联网上。当它不面向互联网时,无论查询语句如何编写,它都不会出现在外部资产索引中。产品指纹还依赖于 ZoomEye 能从横幅(Banner)或响应中识别出的特征。相比于在横幅中主动宣告其产品的服务,需要身份验证才能返回有效内容或仅显示通用登录页面的管理界面更难被指纹识别。

The app=“Cisco Firepower” result of 2 and the app=“Cisco ASA” result of 114 show that Cisco security products are present in the index, but they are indexed under different fingerprints than the FMC console. VulnCheck counted roughly 300 to 700 FMC instances exposed to the internet in March 2026 and did not update the figure afterward. That range is small compared with the NetScaler or RouterOS populations, and it is consistent with a console that is usually kept internal. The small exposed population does not reduce the severity. It changes the response: the affected systems are more likely to be found through internal inventory than through external search. app=“Cisco Firepower” 的 2 个结果和 app=“Cisco ASA” 的 114 个结果表明,思科安全产品确实存在于索引中,但它们被归类在与 FMC 控制台不同的指纹下。VulnCheck 在 2026 年 3 月统计到约 300 到 700 个暴露在互联网上的 FMC 实例,此后未更新该数据。与 NetScaler 或 RouterOS 的规模相比,这个数字很小,这与通常保持在内部的管理控制台特性相符。暴露规模小并不降低其严重性,但它改变了应对方式:受影响的系统通过内部资产清单发现的可能性,远高于通过外部搜索发现的可能性。

What the exploitation showed

漏洞利用情况分析

Talos attributed activity to three clusters. UAT-12197 deployed a JSP web shell to the CSM Tomcat web root and used a JAR command executor with the built-in OmniQuery.pl script to pull authentication data. UAT-11823, assessed with high confidence as sharing tooling with Sandworm, chained CVE-2026-20079 with the static credential flaw CVE-2026-20316, rewrote license.tmp to execute as root, opened a Netcat reverse shell, and installed a Cyclops Blink variant. UAT-11988, assessed as a Qilin ransomware affiliate, used the static credential to log in and eventually deployed ransomware. CISA added CVE-2026-20079 to the KEV catalog on 9 September 2026 with a federal deadline of 12 September 2026. Talos 将相关活动归因于三个集群。UAT-12197 将 JSP Web Shell 部署到 CSM Tomcat Web 根目录,并使用带有内置 OmniQuery.pl 脚本的 JAR 命令执行器来提取身份验证数据。UAT-11823(被高度确信与 Sandworm 共享工具)将 CVE-2026-20079 与静态凭据漏洞 CVE-2026-20316 串联利用,重写 license.tmp 以 root 权限执行,开启了 Netcat 反向 Shell,并安装了 Cyclops Blink 的变体。UAT-11988(被评估为 Qilin 勒索软件的关联方)利用静态凭据登录并最终部署了勒索软件。CISA 于 2026 年 9 月 9 日将 CVE-2026-20079 加入 KEV 目录,并设定联邦机构的修复截止日期为 2026 年 9 月 12 日。

How to scope this one

如何界定受影响范围

When external search returns little, the response has to come from inside. The sequence that fits this case: 当外部搜索几乎没有结果时,响应必须来自内部。适用于此情况的步骤如下:

  1. Build the inventory from internal sources: configuration management, network monitoring, and firewall rules that permit access to the console.
  2. 从内部来源构建资产清单: 包括配置管理、网络监控以及允许访问控制台的防火墙规则。
  3. Identify which FMC instances accept connections from outside the trusted network. VulnCheck’s range of 300 to 700 internet-exposed instances suggests that most are internal, but the ones that are not are the priority.
  4. 识别哪些 FMC 实例接受来自受信任网络之外的连接。 VulnCheck 统计的 300 到 700 个暴露实例表明大多数是内部的,但那些暴露在外的实例是重中之重。
  5. Check the firmware version against the Cisco hotfix for the exact release branch. The fix is branch-specific across 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.
  6. 根据具体的发布分支,对照思科热修复补丁检查固件版本。 修复补丁针对 7.0、7.2、7.4、7.6、7.7 和 10.0 等不同分支各不相同。
  7. Run the retrospective check. In expert mode, zgrep "package_info.license" /var/log/messages; if the output points to /var/tmp/license.tmp, treat the device as compromised. Also check the CSM Tomcat web root for unexpected JAR files.
  8. 运行回顾性检查。 在专家模式下执行 zgrep "package_info.license" /var/log/messages;如果输出指向 /var/tmp/license.tmp,则应将该设备视为已遭入侵。同时检查 CSM Tomcat Web 根目录是否存在异常的 JAR 文件。
  9. Rotate every credential reachable from FMC. The console stores management credentials for the firewalls it governs.
  10. 轮换所有可从 FMC 访问的凭据。 该控制台存储了其所管理防火墙的管理凭据。
  11. Move management interfaces off the public internet and reach them through a VPN or jump host.
  12. 将管理界面从公共互联网撤下,并通过 VPN 或跳板机进行访问。

The measurement lesson

测量带来的教训

External asset search is effective for products that advertise themselves and sit on the public internet. It is less effective for management planes that are meant to be internal. A zero result from a product fingerprint query is not evidence of absence, and treating it that way would be a mistake. For management consoles, the internal inventory is the authoritative source, and external search is a cross-check for the subset that should never have been exposed. The FMC case is a reminder that the assets most worth finding are often the ones that are hardest to see from outside. 外部资产搜索对于那些主动宣告自身存在并位于公共互联网上的产品非常有效。但对于旨在内部使用的管理平面,其效果则大打折扣。产品指纹查询的零结果并不代表“不存在”,将其视为不存在是一个错误。对于管理控制台而言,内部资产清单才是权威来源,而外部搜索仅是对那些本不该暴露的子集进行交叉核对的手段。FMC 的案例提醒我们:最值得发现的资产,往往也是从外部最难看到的资产。