Cisco Catalyst SD-WAN Manager Arbitrary File Creation Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 6.5 Security Advisory

TL;DR 📌

Cisco published a security advisory. See the Fixed software table below for the version you should upgrade to.

What happened 🕵️‍♂️

A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system.

This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the affected system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected products 🖥️

At the time of publication, this vulnerability affected Cisco SD-WAN Manager, regardless of device configuration.

For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
20.12 Not vulnerable.
20.15 20.15.2
20.16 Not vulnerable.
1.1 Updated fixed release information for releases 20.9 and earlier.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

Use vendor CVSS for prioritization. Consider exposure and asset criticality.

Fast facts ⚡

  • Advisory: cisco-sa-sdwanarbfile-2zKhKZwJ
  • Initial release: 2025-05-07T16:00:00 UTC
  • Last updated: 2025-05-14T20:04:53 UTC

For leadership 🧭

Executive summary. SD-WAN Manager, the central controller for Cisco’s Catalyst SD-WAN fabric, has an API flaw that lets a logged-in attacker write arbitrary files to the system, which could undermine its integrity and management of the wider WAN. There is no workaround, so remediation depends entirely on scheduling the upgrade to a fixed release.

Why it matters:

  • SD-WAN Manager is the central management plane for the Catalyst SD-WAN fabric, so arbitrary file writes on it could affect configuration and control of connected sites
  • The flaw sits in application data API endpoints and stems from improper request validation, allowing directory traversal outside intended storage paths
  • Any authenticated user can trigger it, regardless of device configuration, meaning no separate network foothold or elevated privilege is needed to attempt exploitation
  • With no workaround published, affected systems remain exposed to this path until the software itself is upgraded

Now / Next / Later:

  • Now: Identify every Cisco SD-WAN Manager instance and check its running release against the fixed-release table to see whether it is 20.12, 20.16 (not vulnerable) or needs upgrading (e.g. 20.15 trains before 20.15.2).
  • Next: Schedule and apply the first fixed release for your train during the next maintenance window, since Cisco has confirmed no workaround exists for this issue.
  • Later: Build SD-WAN Manager version tracking into routine patch management so future advisories affecting this platform can be triaged and scheduled without ad hoc discovery.