Executive brief
Cisco Catalyst SD-WAN Manager, a centralized management platform for corporate wide-area networks, contains a vulnerability that allows unauthorized access to sensitive system information. An attacker could exploit this to view internal configuration data or operating system files, potentially leading to further network compromise. This vulnerability has been observed being used in active attacks, making immediate patching or mitigation a high priority.
Technical details
A vulnerability in Cisco Catalyst SD-WAN Manager (formerly vManage) is classified as an Information Exposure (CWE-200). The root cause is insufficient file system access restrictions within the management software. While some descriptions suggest an authenticated 'netadmin' user accessing the 'vshell' is required, the NIST CVSS 3.1 assessment and CISA KEV inclusion indicate an unauthenticated remote attack vector via the system's API is possible. An attacker can exploit this to read sensitive files on the underlying operating system. This vulnerability is actively exploited in the wild. Patches are available in versions 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.2.1.
Affected products
- Cisco Catalyst SD-WAN Manager < 20.9.8.2, 20.10.x < 20.12.5.3, 20.13.x < 20.15.4.2, 20.16.x < 20.18.2.1
Timeline
- 2026-03-04: disclosed: Initial NIST analysis recorded
- 2026-04-20: advisory: Cisco advisory published and CISA KEV inclusion
- 2026-04-20: exploited: Vulnerability confirmed as exploited in the wild by CISA