Executive brief
Cisco Catalyst Center, a management platform for enterprise networks, contains a security flaw that allows an unauthorized person to view sensitive files. By sending a specially crafted web request, an attacker could bypass security restrictions to read internal system data. This could lead to the exposure of configuration details or other sensitive information, though it does not directly allow the attacker to modify the system or cause a service outage.
Technical details
A path traversal vulnerability (CWE-22) exists in Cisco Catalyst Center due to insufficient validation of user-supplied input in HTTP requests. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request to the affected device. Successful exploitation allows the attacker to perform an arbitrary file read from a restricted container on the appliance. The vulnerability affects both hardware and virtual appliances (VMware ESXi, AWS, and Azure). Cisco has released software updates to address this issue, and no workarounds are available.
Affected products
- Cisco Catalyst Center 2.3.7, 3.1.3, 3.1.5, 3.1.6
Timeline
- 2026-07-01: advisory: Initial public release of Cisco advisory cisco-sa-catc-file-read-wLH2vf8X
- 2026-07-01: patched