Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
TL;DR 📌
A medium-severity vulnerability has been identified in the Cisco Catalyst SD-WAN Manager, allowing authenticated local attackers to overwrite arbitrary files on the device. Immediate software updates are recommended as there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the command-line interface (CLI) of the Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage) could allow an authenticated local attacker to overwrite arbitrary files on the local file system of an affected device. This vulnerability arises from improper access controls on files in the local file system. An attacker with valid read-only credentials can exploit this by executing crafted commands, potentially gaining root user privileges.
Affected products 🖥️
The vulnerability specifically affects the Cisco Catalyst SD-WAN Manager. For detailed information on which software releases are vulnerable, please refer to the Fixed Software section of the advisory.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 20.12 | 20.12.5 | |
| ISE / ISE-PIC 20.15 | Migrate to a fixed release. | |
| ISE / ISE-PIC 20.16 | 20.16.1 | |
| ISE / ISE-PIC 1.1 | Updated fixed release information for releases 20.9 and earlier. | |
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 5.5, categorized as medium severity. While it requires local access and valid credentials, the potential for an attacker to gain root privileges makes it a risk that should not be overlooked. Organizations using affected versions of the Cisco Catalyst SD-WAN Manager should prioritize applying the necessary updates.
Fast facts ⚡
- Vulnerability: Arbitrary File Overwrite
- CVSS Score: 5.5 (Medium)
- Affected Product: Cisco Catalyst SD-WAN Manager
- Exploitation: Requires local access and valid read-only credentials.
- Workarounds: None available.
For leadership 🧭
Executive summary. An attacker who already holds a low-privilege, read-only login to Catalyst SD-WAN Manager can escalate to root by overwriting files through the CLI, giving them full control of the network’s SD-WAN control plane. There is no workaround, so this should be scheduled into the next available change window rather than left pending.
Why it matters:
- Catalyst SD-WAN Manager (formerly vManage) is the central control point for SD-WAN fabrics, so root compromise here threatens configuration, routing policy and visibility across every managed site.
- The flaw only needs a valid read-only credential, a privilege level often handed out for monitoring or auditing purposes, making the barrier to escalation lower than for most root-privilege bugs.
- With no workaround available, the file-overwrite path in the CLI stays open on unpatched systems until the software is upgraded.
- Because exploitation relies on local CLI access rather than a network-facing service, any account with SD-WAN Manager login rights should be treated as a potential escalation route, not just administrative ones.
Now / Next / Later:
- Now: Review who holds read-only or higher CLI credentials on Catalyst SD-WAN Manager and tighten that list to only those who need it.
- Next: Upgrade affected Catalyst SD-WAN Manager instances to the first fixed release identified for your version train during the next change window.
- Later: Build periodic reviews of SD-WAN Manager account privileges into standard operations, since this flaw shows that even read-only access can be a stepping stone to root.