Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.9 Security Advisory

TL;DR 📌

A vulnerability in the Cisco Catalyst SD-WAN Manager could allow an unauthenticated remote attacker to access sensitive information due to improper certificate validation. Cisco has released updates to address this issue, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability has been identified in the certificate validation processing of Cisco Catalyst SD-WAN Manager, previously known as Cisco SD-WAN vManage. This flaw could enable an unauthenticated remote attacker to exploit improper validation of certificates used by the Smart Licensing feature. By intercepting traffic sent over the Internet, an attacker could potentially gain access to sensitive information, including device credentials for connecting to Cisco cloud services.

Affected products 🖥️

The vulnerability affects Cisco Catalyst SD-WAN Manager when it is configured to connect to Smart Licensing services hosted by Cisco. For detailed information on which specific software releases are vulnerable, please refer to the Fixed Software section of the advisory.

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 20.12 20.12.5
ISE / ISE-PIC 20.15 20.15.2
ISE / ISE-PIC 20.16 Not vulnerable.
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The highest CVSS score for this vulnerability is 5.9, categorized as MEDIUM severity. While this indicates a moderate risk, the potential for an attacker to access sensitive information underscores the importance of applying the provided software updates promptly.

Fast facts ⚡

  • Advisory ID: cisco-sa-catalyst-tls-PqnD5KEJ
  • CVSS Score: 5.9 (MEDIUM)
  • Vulnerability Type: Certificate Validation
  • Exploitation: Possible via privileged network position
  • No workarounds available

For leadership 🧭

Executive summary. An attacker able to intercept traffic between SD-WAN Manager and Cisco’s Smart Licensing service could capture device credentials without needing to authenticate first. There’s no workaround, so this needs a scheduled upgrade rather than an emergency response.

Why it matters:

  • The flaw sits in how SD-WAN Manager validates certificates for its Smart Licensing connection to Cisco cloud services, not in general TLS handling elsewhere on the box.
  • An unauthenticated attacker with a privileged network position on that Internet-bound path could harvest device credentials used to talk to Cisco’s licensing infrastructure.
  • Cisco has published no mitigating configuration change, so exposure persists until the affected release is upgraded.
  • The CVSS score of 5.9 reflects a confidentiality-only impact, but the credentials at stake are what the device uses to authenticate to Cisco’s cloud, making theft worth taking seriously.

Now / Next / Later:

  • Now: Identify every Cisco Catalyst SD-WAN Manager instance configured to use Smart Licensing and confirm its current software release against the advisory’s fixed versions.
  • Next: Schedule an upgrade to the first fixed release for your train during the next maintenance window, since no interim workaround exists.
  • Later: Add certificate-validation checks for cloud-connected licensing and management features to routine patch reviews, so similar gaps are caught before an advisory is needed.