Cisco IOS XE SD-WAN Software Packet Filtering Bypass Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.3 Security Advisory

TL;DR 📌

A medium-severity vulnerability has been identified in Cisco IOS XE SD-WAN Software that allows unauthenticated remote attackers to bypass Layer 3 and Layer 4 traffic filters. This could lead to unauthorized access to network resources. Users are advised to implement workarounds or upgrade to fixed software versions as soon as possible.

What happened 🕵️‍♂️

A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This issue arises from improper traffic filtering conditions on affected devices. By sending a crafted packet, an attacker could exploit this vulnerability to inject malicious packets into the network. Proof-of-concept exploit code is available, although there are no known instances of malicious exploitation at this time.

Affected products 🖥️

The following products are affected by this vulnerability:

  • Cisco IOS XE Software releases 17.2.1r and later in Controller mode.
  • Standalone Cisco IOS XE SD-WAN Software releases:
    • 16.9.1 through 16.9.4
    • 16.10.1 through 16.10.5
    • 16.11.1a
    • 16.12.2r through 16.12.4

Devices with SNMP enabled on any SD-WAN Tunnel interface are also vulnerable. If SNMP is not enabled, the device is not affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.1 Clarified the vulnerable configuration.
1.0 Initial public release.
Cisco IOS and IOS XE Software Not specified

Workarounds 🧯

To mitigate this vulnerability, users can implement the following workarounds:

  1. Configure an extended access control list (ACL) to block and allow specific ingress and egress traffic to and from the device.
  2. Configure a device access policy to block unsolicited SNMP traffic.

These workarounds should be tested in your environment to ensure they do not negatively impact functionality or performance.

Risk in context 🎯

With a CVSS score of 5.3, this vulnerability is rated as Medium severity. The exposure is primarily driven by the fact that it is internet-facing and does not require authentication for exploitation. While the risk is moderate, the potential for unauthorized access to network resources necessitates prompt action.

Fast facts ⚡

  • Vulnerability: Packet Filtering Bypass
  • CVSS Score: 5.3 (Medium)
  • Exploitation: Proof-of-concept code available
  • SNMP Requirement: Vulnerable only if SNMP is enabled
  • Workarounds: ACL configuration and device access policy adjustments

For leadership 🧭

Executive summary. Devices running affected Cisco IOS XE SD-WAN releases with SNMP enabled on a tunnel interface can have their traffic filtering rules bypassed by an unauthenticated remote attacker, allowing unwanted packets into the network. Proof-of-concept code exists, so affected devices should be checked and mitigated within the next routine change cycle rather than left until the next scheduled upgrade.

Why it matters:

  • Affects Cisco IOS XE Software 17.2.1r and later in Controller mode, plus standalone SD-WAN releases from 16.9.1 through 16.12.4, a wide range of in-service SD-WAN deployments.
  • Exploitation requires no authentication and only a crafted packet, and the flaw specifically defeats the Layer 3/4 ACLs administrators rely on to segment or restrict traffic.
  • The bypass only applies where SNMP is enabled on an SD-WAN tunnel interface, so identifying which devices have SNMP configured there is the key exposure question.
  • Proof-of-concept exploit code is already available, increasing the chance of opportunistic probing even though no active exploitation has been reported.

Now / Next / Later:

  • Now: Audit SD-WAN devices to identify which have SNMP enabled on any SD-WAN Tunnel interface, since those are the only ones affected.
  • Next: On affected devices, apply the extended ACL to control ingress/egress traffic and configure a device access policy to block unsolicited SNMP traffic, testing both in a change window.
  • Later: Plan and schedule upgrades to the first fixed release for each affected train, and review whether SNMP needs to be enabled on tunnel interfaces at all going forward.